I received a notification from my internet provider saying that a device on my home network appears to be running a publicly accessible CPE WAN Management Protocol (CWMP) service that could potentially be abused. They could not identify which device triggered the alert and recommended scanning every computer, phone, tablet, sensor, and other device connected to my Wi-Fi for malware. They also suggested checking my network security and making sure only authorized users can connect.
I use a provider-supplied CODA-4680-TPIA router, but I cannot find any setting that lets me disable this management service or view port mappings. I also ran an Nmap scan from outside the network and found no open ports. I am unsure whether this is a problem with the router, malware on one of our devices, or possibly a fraudulent message. My daughter recently installed something on her laptop, so I would appreciate advice on where to start and what I should ask my ISP.
3 Answers
The wording does not automatically mean your daughter installed malware. CWMP is most commonly associated with modems and routers, not ordinary laptops. Still, update the operating system and run a reputable security scan on the laptop and other computers. Change the Wi-Fi password if you suspect unauthorized access, remove unknown devices from the router’s client list, and make sure the router firmware is current.
CWMP is normally a router or modem management protocol used by an ISP to configure, update, and monitor provider-owned equipment. Because this is a supplied CODA-4680-TPIA modem/router, you may not have access to the setting that controls it. Contact the ISP using the phone number or support page listed on its official website and ask whether the alert refers to your modem’s CWMP service, what source address and port they detected, and whether they can confirm or remediate it. Do not reply directly to the original message until you verify that it is genuine.
Treat the notification cautiously because security warnings can be spoofed. Do not click links, open attachments, install software recommended by the message, or provide account details in response. Verify the alert by logging into your ISP account independently or calling official support. Ask them whether the exposure is on their equipment, whether remote administration is required for service, and whether they can replace or reconfigure the modem if it is misconfigured.

I checked the router interface and cannot find port forwarding or a WAN-management option. An external Nmap scan also reported no open ports, so I will contact the ISP through its official support channel and ask them for the exact details.