Skip to main content

Port Details

Port
7547
Transport
TCP
Service
TR-069
IANA service name
cwmp
Range
User port (1024-49151)

Security Exposure

Shadowserver states that it is unlikely CWMP needs to be exposed to the wider internet and that CWMP vulnerabilities can be abused by IoT botnets such as Mirai. In November 2016 a Mirai variant scanned port 7547 and exploited TR-069 and TR-064 flaws in routers, which NSFOCUS linked to the outage of Deutsche Telekom customer routers.

Hardening

  • +Limit inbound 7547 on CPE devices to the ISP's ACS address ranges.
  • +Keep router firmware current and replace devices that no longer receive updates.
  • +Use SSL/TLS with certificate-based authentication between the CPE and the ACS, as TR-069 provides.
  • +Make sure TR-064, a LAN-side configuration protocol, is not reachable on the WAN side.

Monitoring

Track inbound connection attempts to TCP 7547 from addresses outside the ACS ranges and watch for spikes in scanning of that port.

Tools for Auditing and Monitoring TR-069

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Shodan

Freemium
Open Source Intelligence Tools

Search engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.

LicenseProprietary (service); MIT (Python client)
PlatformWeb, Linux, macOS, Windows

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

What is port 7547?→

It is the IANA-assigned port for the Broadband Forum CPE WAN Management Protocol (TR-069), used by ISPs to manage customer routers.

Why is port 7547 open on a home router?→

The ISP's management system connects to the router on 7547 for remote configuration. Shadowserver recommends blocking external access when it is not needed.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 7547 is not guaranteed to be TR-069. Exploited-in-the-wild data from the CISA KEV catalog (CC0).