S4E just found a high-severity finding from top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 27, 2025

Broadcom Router Information Disclosure Scanner

Targets the backup configuration endpoint on Broadcom routers, allowing attackers to retrieve sensitive network settings and credentials.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
Detail

Broadcom routers are widely deployed in residential and corporate networks to manage internet connectivity and local traffic. Network administrators and IT professionals rely on these devices for reliable data routing and network segmentation. Internet service providers often bundle Broadcom routers with their services due to their robust performance and advanced features. Home users benefit from intuitive interfaces for managing Wi-Fi and connected devices. The routers handle critical tasks like DHCP, DNS, and firewall policies, making them central to network operations.

An information disclosure vulnerability arises when sensitive data is inadvertently exposed to unauthorized parties. In Broadcom routers, this occurs due to insecure default configurations or improper access controls on backup files. Attackers can exploit this by accessing unprotected endpoints that serve configuration backups without authentication. The vulnerability stems from the router's web interface exposing backup files in a publicly accessible directory, often without encryption or access restrictions.

Specifically, the vulnerability targets the /backup or /config-backup endpoint on the router's administrative interface. By sending a simple HTTP GET request to this endpoint, an attacker can retrieve a file containing the router's full configuration, including admin credentials, SSID keys, and VPN settings. The backup file is typically stored in plaintext or weakly encrypted format, making it trivial to parse. No authentication or session token is required to access this endpoint, leaving it open to anyone on the network.

If exploited, an attacker gains complete visibility into the router's configuration, enabling them to extract Wi-Fi passwords, admin login credentials, and network topology details. This can lead to unauthorized network access, data interception, and further lateral movement within the organization. For home users, it compromises personal privacy and device control. The CVSS score of 7.8 reflects the high impact and ease of exploitation, as no special privileges or user interaction are needed.

Solution Advice
  • Disable public access to backup configuration files by removing or restricting the /backup endpoint.
  • Implement strong authentication for all administrative interfaces, including backup retrieval.
  • Encrypt backup files using AES-256 or similar before storage or transmission.
  • Update router firmware to the latest version to patch known information disclosure vulnerabilities.
  • Conduct regular security audits to identify exposed endpoints and misconfigurations.
  • Use network segmentation to isolate router management interfaces from untrusted networks.
  • Enable logging and monitoring for unauthorized access attempts to backup endpoints.
  • Change default admin credentials and disable remote management if not required.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Broadcom Router Info Disclosure Scanner | S4E Free Check