Is anyone familiar with ASUS routers, specifically RT-AC56R or similar? Is the firewall enabled or disabled by default?

I'm seeing one one at a customer with the web interface open to the world on port 80 with username/password = admin/admin. Apparently this is what happens if the firewall is disabled, even though web mgmt from WAN is set to NO. If you set it to YES, it creates a port forward from port 80 to port 8080, and now it responds on both ports. To disable remote mgmt and WAN ping, it seems the firewall has to be enabled, which is not how most NAT routers work.

I'm just trying to figure out if the customer turned off the firewall (unlikely given his technical skill level), or if ASUS ships their routers that way. They seem to ship the WiFi unsecured so I guess anything's possible.

Reply via email to