My internet provider sent me a security notice saying that a device on my home network appears to have a publicly accessible CPE WAN Management Protocol (CWMP) service that could potentially be abused. They could not identify which device was affected and suggested scanning computers, phones, tablets, smart devices, and other equipment for malware. They also recommended checking that my Wi-Fi is secured and that only authorized people can connect.
I use a CODA-4680-TPIA modem/router, but I cannot find any setting to disable this service or any port mappings. I ran an Nmap scan from a penetration-testing tool and it reported no open ports. Could this be a problem with the ISP-provided modem itself, or should I be looking for malware on one of our computers? I also want to make sure the message was legitimate before taking action.
1 Answer
Treat the message as potentially legitimate but verify it independently, since security notices can also be spoofed. Do not click links, call numbers, or provide account details from the message itself. A real provider should be able to locate the alert in your account and explain exactly what they detected. If they confirm it, ask them to secure the WAN-side management service or update and replace the modem. A normal CWMP warning by itself is not evidence that malware was installed on a laptop.

Related Questions
Lenovo Thinkpad Stuck In Update Loop Install FilterDriverU2_Reload