Port 7547TR-069 CPE WAN Management

The TR-069 CPE WAN Management Protocol enables ISPs to remotely configure, monitor, and manage customer-premises equipment (CPE) like routers and modems. Widely used in broadband deployments, it facilitates automated provisioning and firmware updates, streamlining service delivery and support. While convenient, its exposure requires careful security management..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
8,267

rank 606 of 993 · top 61%

Technical Details

what runs on :7547

TR-069, also known as CPE WAN Management Protocol (CWMP), is a technical specification designed to enable efficient communication between customer-premises equipment (CPE)—such as home routers, gateways, and modems—and an Auto Configuration Server (ACS) operated by an Internet Service Provider (ISP). The protocol is built over SOAP/HTTP(S) and leverages XML for message formatting, providing a standardized way for ISPs to automate deployment, diagnostics, and servicing of broadband devices.

CWMP specifies a bidirectional communication model where the CPE acts as an HTTP(S) client, initiating connections to the ACS to request configuration changes, firmware updates, or transmit status information. It supports remote management tasks such as initial device provisioning, dynamic service updates, performance monitoring, fault management, and software management, all coordinated by the ACS.

Typically, TR-069 communications occur over TCP port 7547, though the implementation may employ UDP in some cases for discovery or notifications. While many xDSL and broadband providers have this port enabled by default, actual usage varies, with some ISPs disabling remote management or restricting access to internal management networks.

Security Information

exposure of :7547

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

remote access averages 4.0 across 110 ports — this one sits level with it.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Exposure of TR-069 services to the public internet can lead to unauthorized remote management, enabling attackers to manipulate device configurations, intercept traffic, or deploy malware.
  • Weak or default authentication credentials in the ACS or CPE increase susceptibility to brute-force attacks.
  • Vulnerabilities in SOAP message parsing or ACS software can be exploited for command injection or denial of service.
  • Some Mirai botnet variants have abused open port 7547 to compromise broadband devices.

Common Mitigations:

  • Restrict TR-069 access to trusted IP ranges or internal management networks using firewall rules.
  • Enforce strong authentication and password policies for CPE and ACS interfaces.
  • Prefer encrypted communications (HTTPS) rather than plaintext HTTP.
  • Regularly update ACS and firmware to patch known vulnerabilities.
  • Disable TR-069 if remote management is not used or required, or limit features to reduce attack surface.

the 8 most looked-up other ports in remote access — 110 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted