Example report · Authorized Linux lab · SunsetScan v2.1.1

SunsetScan Security Report

Network Security & Lifecycle Assessment Tool • v2.1.1
192.0.2.212 2026-05-28 15:08:53
Profile: FULL
2026-05-28 15:08:53Scan Date
2m 17sDuration
FULLScan Profile
1 / 1Hosts Up
96Total Findings
v2.1.1SunsetScan Version
Severity Dashboard
1
Critical
12
High
39
Medium
17
Low
27
Info
1
Hosts Scanned
1
Hosts Online
13
Open Ports
96
Total Findings
📄 Executive Summary
Immediate action required — 1 critical issue(s) detected

SunsetScan scanned 1 active device(s) on 192.0.2.212 using the FULL profile and found 87 device finding(s); 9 network-level check(s) were recorded. Devices online: 192.0.2.212 (Linux 4.15 - 5.6).

  • 1 critical finding(s) — requires immediate remediation
  • 12 high-severity finding(s) — remediate within 7 days
  • 39 medium-severity finding(s) — schedule for next maintenance window
  • 17 low-severity finding(s) — address when convenient
  • Category with most issues: End-of-Life Software (5 finding(s))
  • Category with most issues: Authentication (3 finding(s))
  • Category with most issues: SSH (2 finding(s))
  • Highest-risk device: 192.0.2.212 — Risk score 100/100 (Critical Risk)

Recommended next step: Immediately address critical findings: change default credentials, disable SMBv1, and apply available security patches. Isolate any device with a CRITICAL finding until remediated.

🎯 Device Risk Scores
100
192.0.2.212
Critical Risk
87 finding(s)
Top: Anonymous FTP login allowed on port 2121, Telnet-like remote login service detected on...
12
192.0.2.1
Low Risk
2 finding(s)
Top: UPnP Internet Gateway Device (router) found..., UPnP device found: RT-AX92U-7130
12
192.0.2.61
Low Risk
3 finding(s)
Top: UPnP-enabled device at 192.0.2.61: Nas (DS224+), mDNS-only device discovered: 192.0.2.61...
7
192.0.2.181
Minimal Risk
1 finding(s)
Top: mDNS-only device discovered: 192.0.2.181 [Sovrum]
5
192.0.2.84
Minimal Risk
2 finding(s)
Top: UPnP-enabled device at 192.0.2.84: WPS..., UPnP device found: WPS Access Point
🌐 Network Topology
192.0.2.212
Router
TP-Link Archer C7
v3.15.1 Build 160616
LabHost
00:00:00:00:00:00
1 Critical
Risk: 100/100 — Critical Risk
13 open port(s): 22, 53, 80, 443, 2121, 2222, 2323, 5000, 5555, 8080, 8088, 8089, 8090
🔎 Device Inventory
IP Address Name Type Vendor Model Version Firmware EOL Confidence Sources
192.0.2.212 LabHost Router TP-Link Archer C7 3.15.1 Build 160616 — 100% active:credentials_model_index, active:http_fingerprint, mdns, oui, history
⚙ All Findings (sorted by severity)
Severity Host Port Category Finding
CRITICAL 192.0.2.212 2121/FTP Authentication Anonymous FTP login allowed on port 2121
HIGH 192.0.2.1 1900/UDP UPnP UPnP Internet Gateway Device (router) found at 192.0.2.1
HIGH 192.0.2.212 Hardware Lifecycle TP-Link Archer C7 no longer receives security updates
HIGH 192.0.2.212 22/SSH SSH SSH weak MAC algorithms supported on port 22
HIGH 192.0.2.212 22/SSH SSH SSH weak ciphers supported on port 22
HIGH 192.0.2.212 2323/TCP Insecure Protocols Telnet-like remote login service detected on port 2323
HIGH 192.0.2.212 5000/HTTP Authentication Login form on plain HTTP — credentials sent in cleartext
HIGH 192.0.2.212 5000/TCP End-of-Life Software End-of-Life software: php 7.2.34
HIGH 192.0.2.212 5555/TCP End-of-Life Software End-of-Life software: redis 5.0.14
HIGH 192.0.2.212 8080/HTTP Authentication Login form on plain HTTP — credentials sent in cleartext
HIGH 192.0.2.212 8080/TCP End-of-Life Software End-of-Life software: nginx 1.14.0
HIGH 192.0.2.212 8088/TCP End-of-Life Software End-of-Life software: nginx 1.14.0
HIGH 192.0.2.212 8090/TCP End-of-Life Software End-of-Life software: php 7.2.34
MEDIUM 192.0.2.61 445/UDP mDNS Discovery mDNS-only device discovered: 192.0.2.61 [Nas.local.]
MEDIUM 192.0.2.61 1900/UDP UPnP UPnP-enabled device at 192.0.2.61: Nas (DS224+)
MEDIUM 192.0.2.84 1900/UDP UPnP UPnP-enabled device at 192.0.2.84: WPS Access Point
MEDIUM 192.0.2.181 5353/UDP mDNS Discovery mDNS-only device discovered: 192.0.2.181 [Sovrum]
MEDIUM 192.0.2.212 80/HTTP Web Interface Admin panel paths found on port 80
MEDIUM 192.0.2.212 443/HTTPS HTTP Security Headers Missing HSTS header
MEDIUM 192.0.2.212 443/HTTPS Web Interface Admin panel paths found on port 443
MEDIUM 192.0.2.212 2121/FTP Encryption FTP has no TLS support (cleartext credentials) on port 2121
MEDIUM 192.0.2.212 2121/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2011-0762 in vsftpd 2.3.4
MEDIUM 192.0.2.212 2121/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2011-2189 in vsftpd 2.3.4
MEDIUM 192.0.2.212 2121/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2015-1419 in vsftpd 2.3.4
MEDIUM 192.0.2.212 2121/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2021-3618 in vsftpd 2.3.4
MEDIUM 192.0.2.212 5000/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 5000/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 5000/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 5000/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 5000/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 5000/HTTP Web Interface Admin panel paths found on port 5000
MEDIUM 192.0.2.212 8080/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16843 in nginx 1.14.0
MEDIUM 192.0.2.212 8080/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16844 in nginx 1.14.0
MEDIUM 192.0.2.212 8080/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16845 in nginx 1.14.0
MEDIUM 192.0.2.212 8080/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2019-20372 in nginx 1.14.0
MEDIUM 192.0.2.212 8080/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2019-9511 in nginx 1.14.0
MEDIUM 192.0.2.212 8080/HTTP Web Interface Admin panel paths found on port 8080
MEDIUM 192.0.2.212 8088/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16843 in nginx 1.14.0
MEDIUM 192.0.2.212 8088/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16844 in nginx 1.14.0
MEDIUM 192.0.2.212 8088/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2018-16845 in nginx 1.14.0
MEDIUM 192.0.2.212 8088/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2019-20372 in nginx 1.14.0
MEDIUM 192.0.2.212 8088/TCP Known Vulnerabilities (CVE) Known vulnerability: ALPINE-CVE-2019-9511 in nginx 1.14.0
MEDIUM 192.0.2.212 8089/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 8089/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 8089/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 8089/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 8089/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.49
MEDIUM 192.0.2.212 8090/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.38
MEDIUM 192.0.2.212 8090/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.38
MEDIUM 192.0.2.212 8090/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.38
MEDIUM 192.0.2.212 8090/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.38
MEDIUM 192.0.2.212 8090/TCP Known Vulnerabilities (CVE) Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.38
LOW 192.0.2.212 443/HTTPS SSL/TLS TLS certificate expiring in 41 days
LOW 192.0.2.212 2222/SSH SSH SSH algorithm enumeration failed on port 2222 — manual verification recommended
LOW 192.0.2.212 5000/HTTP HTTP Security Headers Missing Content-Security-Policy header
LOW 192.0.2.212 5000/HTTP HTTP Security Headers Missing X-Content-Type-Options header
LOW 192.0.2.212 5000/HTTP HTTP Security Headers Missing X-Frame-Options header
LOW 192.0.2.212 8080/HTTP HTTP Security Headers Missing Content-Security-Policy header
LOW 192.0.2.212 8080/HTTP HTTP Security Headers Missing X-Content-Type-Options header
LOW 192.0.2.212 8080/HTTP HTTP Security Headers Missing X-Frame-Options header
LOW 192.0.2.212 8088/HTTP HTTP Security Headers Missing Content-Security-Policy header
LOW 192.0.2.212 8088/HTTP HTTP Security Headers Missing X-Content-Type-Options header
LOW 192.0.2.212 8088/HTTP HTTP Security Headers Missing X-Frame-Options header
LOW 192.0.2.212 8089/HTTP HTTP Security Headers Missing Content-Security-Policy header
LOW 192.0.2.212 8089/HTTP HTTP Security Headers Missing X-Content-Type-Options header
LOW 192.0.2.212 8089/HTTP HTTP Security Headers Missing X-Frame-Options header
LOW 192.0.2.212 8090/HTTP HTTP Security Headers Missing Content-Security-Policy header
LOW 192.0.2.212 8090/HTTP HTTP Security Headers Missing X-Content-Type-Options header
LOW 192.0.2.212 8090/HTTP HTTP Security Headers Missing X-Frame-Options header
INFO 192.0.2.1 1900/UDP UPnP UPnP device found: RT-AX92U-7130
INFO 192.0.2.61 1900/UDP UPnP UPnP device found: Nas (DS224+)
INFO 192.0.2.84 1900/UDP UPnP UPnP device found: WPS Access Point
INFO 192.0.2.212 Device Identification Device identified: Router — TP-Link — Archer C7 — v3.15.1 Build 160616
INFO 192.0.2.212 22/SSH SSH SSH service detected: OpenSSH 10.0p2
INFO 192.0.2.212 80/HTTP Web Interface Web interface detected: Pi-hole LabHost
INFO 192.0.2.212 443/HTTPS SSL/TLS JA3S fingerprint computed on port 443
INFO 192.0.2.212 443/HTTPS SSL/TLS TLS certificate: CN=pi.hole
INFO 192.0.2.212 443/HTTPS Web Interface Web interface detected: Pi-hole LabHost
INFO 192.0.2.212 2121/FTP FTP FTP service detected: vsftpd 2.3.4
INFO 192.0.2.212 2222/SSH SSH SSH service detected: OpenSSH 7.4
INFO 192.0.2.212 5000/HTTP Web Interface Web interface detected: Legacy Apache Test App
INFO 192.0.2.212 5000/HTTP Web Technology Web technology detected: Apache HTTP Server 2.4.49
INFO 192.0.2.212 5000/HTTP Web Technology Web technology detected: PHP 7.2.34
INFO 192.0.2.212 8080/HTTP Web Interface Web interface detected: TP-Link Archer C7
INFO 192.0.2.212 8080/HTTP Web Technology Web technology detected: Nginx 1.14.0
INFO 192.0.2.212 8080/HTTP Web Technology Web technology detected: PHP 7.2.34
INFO 192.0.2.212 8088/HTTP Web Interface Web interface detected: Welcome to nginx!
INFO 192.0.2.212 8088/HTTP Web Technology Web technology detected: Nginx 1.14.0
INFO 192.0.2.212 8089/HTTP Web Interface Web interface detected: no title
INFO 192.0.2.212 8089/HTTP Web Technology Web technology detected: Apache HTTP Server 2.4.49
INFO 192.0.2.212 8089/HTTP Web Technology Web technology detected: UNIX
INFO 192.0.2.212 8090/HTTP Web Interface Web interface detected: phpinfo()
INFO 192.0.2.212 8090/HTTP Web Technology Web technology detected: Apache HTTP Server 2.4.38
INFO 192.0.2.212 8090/HTTP Web Technology Web technology detected: Debian
INFO 192.0.2.212 8090/HTTP Web Technology Web technology detected: PHP 7.2.34
INFO local 53/UDP DNS Security DNS responses match trusted resolver — no hijacking detected
🔭 Host Details
192.0.2.212 LabHost • TP-Link Archer C7 (Router)
1 Critical 11 High 35 Medium 17 Low Risk 100/100 ▼
MAC: 00:00:00:00:00:00 OS: Linux 4.15 - 5.6 (100% confidence) State: up Open ports: 13
Router — TP-Link Archer C7 v3.15.1 Build 160616 100% confidence
CRITICAL Anonymous FTP login allowed on port 2121 2121/FTP
What was found
The FTP server on port 2121 accepted a login with username 'anonymous' and no real password. Any user on the network can browse and download files.
What this means
Anonymous FTP allows anyone to connect without credentials. This is almost always unintentional on home and office networks and can expose sensitive files to anyone on the local network or internet.
What to do
1. Disable anonymous FTP access immediately in the server configuration. 2. If anonymous access is required (e.g., public software mirror), ensure no sensitive files are in the FTP root. 3. Consider switching to SFTP which enforces authentication and encryption.
Evidence: Anonymous login succeeded. Welcome: '220 (vsFTPd 2.3.4)'
HIGH TP-Link Archer C7 no longer receives security updates LIKELY
What was found
TP-Link Archer C7 matched hardware lifecycle data with status 'unsupported'. Security/support updates ended on 2017-12-31.
What this means
Vendor lifecycle data indicates this hardware no longer receives security updates on 2017-12-31. New vulnerabilities may remain unpatched even if the device's exposed services are configured correctly.
What to do
1. Confirm the exact model, hardware revision, and region from the device label or admin UI. 2. Apply the newest firmware still offered by the vendor. 3. If the vendor no longer provides security updates for this hardware, plan replacement or isolate the device on a restricted network segment.
Evidence: Hardware EOL records: hw_tplink_2a54c23c924ff4ce, hw_tplink_30fd65b4223a97aa, hw_tplink_365180a5e1734e89, hw_tplink_36f0703e1cd7c06d, hw_tplink_6883355b4570d79f, +3 more; security EOL date: 2017-12-31; hardware revision seen: v2.0; source: https://static.tp-link.com/upload/manual/2026/202602/20260228/EOL%20List_Home%20Networking%20-%20V7.0.pdf
HIGH SSH weak MAC algorithms supported on port 22 22/SSH
What was found
The SSH server supports weak MAC algorithms: hmac-sha1, hmac-md5, hmac-sha1-96, hmac-md5-96
What this means
HMAC-MD5 and HMAC-SHA1 are deprecated and considered weak for integrity protection. Modern SSH should use ETM (encrypt-then-MAC) variants.
What to do
In sshd_config, set: MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com
Evidence: Weak MACs advertised: hmac-sha1, hmac-md5, hmac-sha1-96, hmac-md5-96
HIGH SSH weak ciphers supported on port 22 22/SSH
What was found
The SSH server supports weak or broken ciphers: 3des-cbc
What this means
RC4 (arcfour) is a broken stream cipher banned by RFC 7465. 3DES-CBC is vulnerable to Sweet32 birthday attacks. The 'none' cipher transmits data completely unencrypted.
What to do
In sshd_config, set: Ciphers aes256-gcm@openssh.com,aes128-gcm@openssh.com,chacha20-poly1305@openssh.com
Evidence: Weak ciphers advertised: 3des-cbc
HIGH Telnet-like remote login service detected on port 2323 2323/TCP
What was found
Port 2323 appears to expose a Telnet-style remote login service.
What this means
Telnet-style login services transmit sessions without modern transport encryption unless wrapped by another security layer. Credentials and commands can be captured by anyone able to observe the network path.
What to do
Disable the Telnet-style service or replace it with SSH. If the service is required for legacy equipment, restrict it to a management VLAN or specific administration hosts with firewall rules.
Evidence: BusyBox v1.19.4 (2012-03-15) built-in shell (ash) lab-router login:
HIGH Login form on plain HTTP — credentials sent in cleartext 5000/HTTP
What was found
Port 5000 serves an HTML login form over plain HTTP. Any password entered here is transmitted without encryption.
What this means
This web interface has a username/password login form but uses plain HTTP instead of HTTPS. Any password typed into this form is sent across the network without any encryption. Anyone else on the same Wi-Fi network could capture those credentials using freely available tools.
What to do
1. Access this device's settings and enable HTTPS. 2. If the device doesn't support HTTPS, check for a firmware update. 3. Until this is fixed, only administer this device from a wired connection, not over Wi-Fi.
Evidence: Password input field found at: http://192.0.2.212:5000/
HIGH End-of-Life software: php 7.2.34 5000/TCP
What was found
php 7.2.34 reached EOL on 2020-11-30
What this means
php 7.2.34 reached End-of-Life on 2020-11-30. The vendor no longer releases security patches for this version. Any new vulnerabilities discovered will remain unpatched forever.
What to do
Upgrade php to the latest supported version (7.2.34). If this is a network device (router, NAS, printer), check the manufacturer's website for a firmware update or replacement options.
Evidence: Product: php 7.2.34
HIGH End-of-Life software: redis 5.0.14 5555/TCP
What was found
redis 5.0.14 reached EOL on 2022-04-27
What this means
redis 5.0.14 reached End-of-Life on 2022-04-27. The vendor no longer releases security patches for this version. Any new vulnerabilities discovered will remain unpatched forever.
What to do
Upgrade redis to the latest supported version (5.0.14). If this is a network device (router, NAS, printer), check the manufacturer's website for a firmware update or replacement options.
Evidence: Product: redis 5.0.14
HIGH Login form on plain HTTP — credentials sent in cleartext 8080/HTTP
What was found
Port 8080 serves an HTML login form over plain HTTP. Any password entered here is transmitted without encryption.
What this means
This web interface has a username/password login form but uses plain HTTP instead of HTTPS. Any password typed into this form is sent across the network without any encryption. Anyone else on the same Wi-Fi network could capture those credentials using freely available tools.
What to do
1. Access this device's settings and enable HTTPS. 2. If the device doesn't support HTTPS, check for a firmware update. 3. Until this is fixed, only administer this device from a wired connection, not over Wi-Fi.
Evidence: Password input field found at: http://192.0.2.212:8080/
HIGH End-of-Life software: nginx 1.14.0 8080/TCP
What was found
nginx 1.14.0 reached EOL on 2019-04-23
What this means
nginx 1.14.0 reached End-of-Life on 2019-04-23. The vendor no longer releases security patches for this version. Any new vulnerabilities discovered will remain unpatched forever.
What to do
Upgrade nginx to the latest supported version (1.14.2). If this is a network device (router, NAS, printer), check the manufacturer's website for a firmware update or replacement options.
Evidence: Product: nginx 1.14.0
HIGH End-of-Life software: nginx 1.14.0 8088/TCP
What was found
nginx 1.14.0 reached EOL on 2019-04-23
What this means
nginx 1.14.0 reached End-of-Life on 2019-04-23. The vendor no longer releases security patches for this version. Any new vulnerabilities discovered will remain unpatched forever.
What to do
Upgrade nginx to the latest supported version (1.14.2). If this is a network device (router, NAS, printer), check the manufacturer's website for a firmware update or replacement options.
Evidence: Product: nginx 1.14.0
HIGH End-of-Life software: php 7.2.34 8090/TCP
What was found
php 7.2.34 reached EOL on 2020-11-30
What this means
php 7.2.34 reached End-of-Life on 2020-11-30. The vendor no longer releases security patches for this version. Any new vulnerabilities discovered will remain unpatched forever.
What to do
Upgrade php to the latest supported version (7.2.34). If this is a network device (router, NAS, printer), check the manufacturer's website for a firmware update or replacement options.
Evidence: Product: php 7.2.34
MEDIUM Admin panel paths found on port 80 80/HTTP
What was found
The following admin-related paths responded on port 80: /admin [accessible], /admin/ [accessible]
What this means
Admin panel paths are accessible on this device. Paths marked 'accessible' returned HTTP 200 without authentication. Paths marked 'protected' exist but require login — ensure strong credentials are in use.
What to do
1. Ensure all admin interfaces require strong authentication. 2. If possible, restrict admin access to specific IP addresses only. 3. Disable or remove any admin paths that are no longer needed. 4. Change any default passwords on accessible admin panels.
Evidence: Paths: /admin [accessible], /admin/ [accessible]
MEDIUM Missing HSTS header 443/HTTPS
What was found
The HTTP response from port 443 is missing the Strict-Transport-Security security header.
What this means
HTTP Strict Transport Security (HSTS) tells browsers to only connect over HTTPS. Without it, users could be tricked into connecting over plain HTTP.
What to do
Add header: Strict-Transport-Security: max-age=31536000; includeSubDomains
Evidence: Header absent from: GET https://192.0.2.212:443/
MEDIUM Admin panel paths found on port 443 443/HTTPS
What was found
The following admin-related paths responded on port 443: /admin [accessible], /admin/ [accessible]
What this means
Admin panel paths are accessible on this device. Paths marked 'accessible' returned HTTP 200 without authentication. Paths marked 'protected' exist but require login — ensure strong credentials are in use.
What to do
1. Ensure all admin interfaces require strong authentication. 2. If possible, restrict admin access to specific IP addresses only. 3. Disable or remove any admin paths that are no longer needed. 4. Change any default passwords on accessible admin panels.
Evidence: Paths: /admin [accessible], /admin/ [accessible]
MEDIUM FTP has no TLS support (cleartext credentials) on port 2121 2121/FTP
What was found
The FTP server on port 2121 does not support AUTH TLS (STARTTLS). Credentials and file transfers are sent in cleartext.
What this means
Without TLS, your FTP username and password are sent across the network unencrypted. Anyone using a network monitoring tool on the same network can capture your FTP credentials.
What to do
1. Enable FTPS (AUTH TLS) in your FTP server configuration. 2. Better: replace FTP entirely with SFTP (port 22, SSH-based). 3. Disable plain FTP if FTPS or SFTP is available.
Evidence: AUTH TLS response was not 234
MEDIUM Known vulnerability: DEBIAN-CVE-2011-0762 in vsftpd 2.3.4 2121/TCP
What was found
DEBIAN-CVE-2011-0762 affects vsftpd 2.3.4 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of vsftpd detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update vsftpd to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: vsftpd 2.3.4; cache key: vsftpd 2.3.4
DEBIAN-CVE-2011-0762
MEDIUM Known vulnerability: DEBIAN-CVE-2011-2189 in vsftpd 2.3.4 2121/TCP
What was found
DEBIAN-CVE-2011-2189 affects vsftpd 2.3.4 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of vsftpd detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update vsftpd to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: vsftpd 2.3.4; cache key: vsftpd 2.3.4
DEBIAN-CVE-2011-2189
MEDIUM Known vulnerability: DEBIAN-CVE-2015-1419 in vsftpd 2.3.4 2121/TCP
What was found
DEBIAN-CVE-2015-1419 affects vsftpd 2.3.4 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of vsftpd detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update vsftpd to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: vsftpd 2.3.4; cache key: vsftpd 2.3.4
DEBIAN-CVE-2015-1419
MEDIUM Known vulnerability: DEBIAN-CVE-2021-3618 in vsftpd 2.3.4 2121/TCP
What was found
DEBIAN-CVE-2021-3618 affects vsftpd 2.3.4 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of vsftpd detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update vsftpd to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: vsftpd 2.3.4; cache key: vsftpd 2.3.4
DEBIAN-CVE-2021-3618
MEDIUM Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.49 5000/TCP
What was found
DEBIAN-CVE-2001-1534 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2001-1534
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.49 5000/TCP
What was found
DEBIAN-CVE-2003-1307 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1307
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.49 5000/TCP
What was found
DEBIAN-CVE-2003-1580 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1580
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.49 5000/TCP
What was found
DEBIAN-CVE-2003-1581 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1581
MEDIUM Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.49 5000/TCP
What was found
DEBIAN-CVE-2006-20001 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2006-20001
MEDIUM Admin panel paths found on port 5000 5000/HTTP
What was found
The following admin-related paths responded on port 5000: /admin [accessible], /admin/ [accessible], /administrator [accessible], /administrator/ [accessible], /setup [accessible], /setup/ [accessible], /config [accessible], /config/ [accessible], /manager [accessible], /manager/html [accessible], /wp-admin [accessible], /wp-admin/ [accessible], /phpmyadmin [accessible], /phpmyadmin/ [accessible], /webadmin [accessible], /webadmin/ [accessible], /cgi-bin/ [accessible], /cgi-bin/admin [accessible], /login [accessible], /login.html [accessible], /login.php [accessible], /dashboard [accessible], /panel [accessible]
What this means
Admin panel paths are accessible on this device. Paths marked 'accessible' returned HTTP 200 without authentication. Paths marked 'protected' exist but require login — ensure strong credentials are in use.
What to do
1. Ensure all admin interfaces require strong authentication. 2. If possible, restrict admin access to specific IP addresses only. 3. Disable or remove any admin paths that are no longer needed. 4. Change any default passwords on accessible admin panels.
Evidence: Paths: /admin [accessible], /admin/ [accessible], /administrator [accessible], /administrator/ [accessible], /setup [accessible], /setup/ [accessible], /config [accessible], /config/ [accessible], /manager [accessible], /manager/html [accessible], /wp-admin [accessible], /wp-admin/ [accessible], /phpmyadmin [accessible], /phpmyadmin/ [accessible], /webadmin [accessible], /webadmin/ [accessible], /cgi-bin/ [accessible], /cgi-bin/admin [accessible], /login [accessible], /login.html [accessible], /login.php [accessible], /dashboard [accessible], /panel [accessible]
MEDIUM Known vulnerability: ALPINE-CVE-2018-16843 in nginx 1.14.0 8080/TCP
What was found
ALPINE-CVE-2018-16843 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16843
MEDIUM Known vulnerability: ALPINE-CVE-2018-16844 in nginx 1.14.0 8080/TCP
What was found
ALPINE-CVE-2018-16844 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16844
MEDIUM Known vulnerability: ALPINE-CVE-2018-16845 in nginx 1.14.0 8080/TCP
What was found
ALPINE-CVE-2018-16845 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16845
MEDIUM Known vulnerability: ALPINE-CVE-2019-20372 in nginx 1.14.0 8080/TCP
What was found
ALPINE-CVE-2019-20372 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2019-20372
MEDIUM Known vulnerability: ALPINE-CVE-2019-9511 in nginx 1.14.0 8080/TCP
What was found
ALPINE-CVE-2019-9511 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2019-9511
MEDIUM Admin panel paths found on port 8080 8080/HTTP
What was found
The following admin-related paths responded on port 8080: /admin [accessible], /admin/ [accessible], /administrator [accessible], /administrator/ [accessible], /setup [accessible], /setup/ [accessible], /config [accessible], /config/ [accessible], /manager [accessible], /manager/html [accessible], /wp-admin [accessible], /wp-admin/ [accessible], /phpmyadmin [accessible], /phpmyadmin/ [accessible], /webadmin [accessible], /webadmin/ [accessible], /cgi-bin/ [accessible], /cgi-bin/admin [accessible], /login [accessible], /login.html [accessible], /login.php [accessible], /dashboard [accessible], /panel [accessible]
What this means
Admin panel paths are accessible on this device. Paths marked 'accessible' returned HTTP 200 without authentication. Paths marked 'protected' exist but require login — ensure strong credentials are in use.
What to do
1. Ensure all admin interfaces require strong authentication. 2. If possible, restrict admin access to specific IP addresses only. 3. Disable or remove any admin paths that are no longer needed. 4. Change any default passwords on accessible admin panels.
Evidence: Paths: /admin [accessible], /admin/ [accessible], /administrator [accessible], /administrator/ [accessible], /setup [accessible], /setup/ [accessible], /config [accessible], /config/ [accessible], /manager [accessible], /manager/html [accessible], /wp-admin [accessible], /wp-admin/ [accessible], /phpmyadmin [accessible], /phpmyadmin/ [accessible], /webadmin [accessible], /webadmin/ [accessible], /cgi-bin/ [accessible], /cgi-bin/admin [accessible], /login [accessible], /login.html [accessible], /login.php [accessible], /dashboard [accessible], /panel [accessible]
MEDIUM Known vulnerability: ALPINE-CVE-2018-16843 in nginx 1.14.0 8088/TCP
What was found
ALPINE-CVE-2018-16843 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16843
MEDIUM Known vulnerability: ALPINE-CVE-2018-16844 in nginx 1.14.0 8088/TCP
What was found
ALPINE-CVE-2018-16844 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16844
MEDIUM Known vulnerability: ALPINE-CVE-2018-16845 in nginx 1.14.0 8088/TCP
What was found
ALPINE-CVE-2018-16845 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2018-16845
MEDIUM Known vulnerability: ALPINE-CVE-2019-20372 in nginx 1.14.0 8088/TCP
What was found
ALPINE-CVE-2019-20372 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2019-20372
MEDIUM Known vulnerability: ALPINE-CVE-2019-9511 in nginx 1.14.0 8088/TCP
What was found
ALPINE-CVE-2019-9511 affects nginx 1.14.0 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of nginx detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update nginx to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: nginx 1.14.0; cache key: nginx 1.14.0
ALPINE-CVE-2019-9511
MEDIUM Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.49 8089/TCP
What was found
DEBIAN-CVE-2001-1534 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2001-1534
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.49 8089/TCP
What was found
DEBIAN-CVE-2003-1307 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1307
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.49 8089/TCP
What was found
DEBIAN-CVE-2003-1580 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1580
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.49 8089/TCP
What was found
DEBIAN-CVE-2003-1581 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2003-1581
MEDIUM Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.49 8089/TCP
What was found
DEBIAN-CVE-2006-20001 affects apache-http-server 2.4.49 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.49; cache key: apache-http-server 2.4.49
DEBIAN-CVE-2006-20001
MEDIUM Known vulnerability: DEBIAN-CVE-2001-1534 in apache-http-server 2.4.38 8090/TCP
What was found
DEBIAN-CVE-2001-1534 affects apache-http-server 2.4.38 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.38; cache key: apache-http-server 2.4.38
DEBIAN-CVE-2001-1534
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1307 in apache-http-server 2.4.38 8090/TCP
What was found
DEBIAN-CVE-2003-1307 affects apache-http-server 2.4.38 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.38; cache key: apache-http-server 2.4.38
DEBIAN-CVE-2003-1307
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1580 in apache-http-server 2.4.38 8090/TCP
What was found
DEBIAN-CVE-2003-1580 affects apache-http-server 2.4.38 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.38; cache key: apache-http-server 2.4.38
DEBIAN-CVE-2003-1580
MEDIUM Known vulnerability: DEBIAN-CVE-2003-1581 in apache-http-server 2.4.38 8090/TCP
What was found
DEBIAN-CVE-2003-1581 affects apache-http-server 2.4.38 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.38; cache key: apache-http-server 2.4.38
DEBIAN-CVE-2003-1581
MEDIUM Known vulnerability: DEBIAN-CVE-2006-20001 in apache-http-server 2.4.38 8090/TCP
What was found
DEBIAN-CVE-2006-20001 affects apache-http-server 2.4.38 (no CVSS score). No description available
What this means
A publicly known security vulnerability exists in the version of apache-http-server detected on this device. This vulnerability has been disclosed publicly, meaning attackers know about it and may have tools to exploit it.
What to do
Update apache-http-server to the latest available version. Check your device vendor's support site for firmware updates.
Evidence: Detected service: apache 2.4.38; cache key: apache-http-server 2.4.38
DEBIAN-CVE-2006-20001
LOW TLS certificate expiring in 41 days 443/HTTPS
What was found
Certificate on port 443 expires in 41 days.
What this means
The TLS certificate expires within 90 days.
What to do
Plan to renew the TLS certificate before it expires.
Evidence: Expires: 2026-07-09
LOW SSH algorithm enumeration failed on port 2222 — manual verification recommended 2222/SSH
What was found
SSH service detected on port 2222 but algorithm enumeration failed. The server may use non-standard client restrictions or a custom SSH stack.
What this means
SSH algorithm enumeration identifies weak or outdated cryptographic settings. Both paramiko and raw socket KEXINIT methods were attempted. When enumeration fails, the cryptographic posture cannot be fully assessed.
What to do
Manually verify SSH configuration: ssh -Q kex <host> ssh-audit <host> (install via pip install ssh-audit) Ensure the server uses modern algorithms and has SSHv1 disabled.
Evidence: Banner: SSH-2.0-OpenSSH_7.4; Paramiko: connection rejected; Raw KEXINIT: no valid response
LOW Missing Content-Security-Policy header 5000/HTTP
What was found
The HTTP response from port 5000 is missing the Content-Security-Policy security header.
What this means
A Content Security Policy helps prevent Cross-Site Scripting (XSS) attacks by controlling which scripts and resources can load.
What to do
Implement a Content-Security-Policy header appropriate for your application.
Evidence: Header absent from: GET http://192.0.2.212:5000/
LOW Missing X-Content-Type-Options header 5000/HTTP
What was found
The HTTP response from port 5000 is missing the X-Content-Type-Options security header.
What this means
This header prevents browsers from guessing (sniffing) the content type. Without it, some attacks using malicious file uploads become easier.
What to do
Add header: X-Content-Type-Options: nosniff
Evidence: Header absent from: GET http://192.0.2.212:5000/
LOW Missing X-Frame-Options header 5000/HTTP
What was found
The HTTP response from port 5000 is missing the X-Frame-Options security header.
What this means
Without X-Frame-Options, this page could be embedded in another website's iframe. This enables clickjacking attacks.
What to do
Add header: X-Frame-Options: DENY (or SAMEORIGIN for admin panels).
Evidence: Header absent from: GET http://192.0.2.212:5000/
LOW Missing Content-Security-Policy header 8080/HTTP
What was found
The HTTP response from port 8080 is missing the Content-Security-Policy security header.
What this means
A Content Security Policy helps prevent Cross-Site Scripting (XSS) attacks by controlling which scripts and resources can load.
What to do
Implement a Content-Security-Policy header appropriate for your application.
Evidence: Header absent from: GET http://192.0.2.212:8080/
LOW Missing X-Content-Type-Options header 8080/HTTP
What was found
The HTTP response from port 8080 is missing the X-Content-Type-Options security header.
What this means
This header prevents browsers from guessing (sniffing) the content type. Without it, some attacks using malicious file uploads become easier.
What to do
Add header: X-Content-Type-Options: nosniff
Evidence: Header absent from: GET http://192.0.2.212:8080/
LOW Missing X-Frame-Options header 8080/HTTP
What was found
The HTTP response from port 8080 is missing the X-Frame-Options security header.
What this means
Without X-Frame-Options, this page could be embedded in another website's iframe. This enables clickjacking attacks.
What to do
Add header: X-Frame-Options: DENY (or SAMEORIGIN for admin panels).
Evidence: Header absent from: GET http://192.0.2.212:8080/
LOW Missing Content-Security-Policy header 8088/HTTP
What was found
The HTTP response from port 8088 is missing the Content-Security-Policy security header.
What this means
A Content Security Policy helps prevent Cross-Site Scripting (XSS) attacks by controlling which scripts and resources can load.
What to do
Implement a Content-Security-Policy header appropriate for your application.
Evidence: Header absent from: GET http://192.0.2.212:8088/
LOW Missing X-Content-Type-Options header 8088/HTTP
What was found
The HTTP response from port 8088 is missing the X-Content-Type-Options security header.
What this means
This header prevents browsers from guessing (sniffing) the content type. Without it, some attacks using malicious file uploads become easier.
What to do
Add header: X-Content-Type-Options: nosniff
Evidence: Header absent from: GET http://192.0.2.212:8088/
LOW Missing X-Frame-Options header 8088/HTTP
What was found
The HTTP response from port 8088 is missing the X-Frame-Options security header.
What this means
Without X-Frame-Options, this page could be embedded in another website's iframe. This enables clickjacking attacks.
What to do
Add header: X-Frame-Options: DENY (or SAMEORIGIN for admin panels).
Evidence: Header absent from: GET http://192.0.2.212:8088/
LOW Missing Content-Security-Policy header 8089/HTTP
What was found
The HTTP response from port 8089 is missing the Content-Security-Policy security header.
What this means
A Content Security Policy helps prevent Cross-Site Scripting (XSS) attacks by controlling which scripts and resources can load.
What to do
Implement a Content-Security-Policy header appropriate for your application.
Evidence: Header absent from: GET http://192.0.2.212:8089/
LOW Missing X-Content-Type-Options header 8089/HTTP
What was found
The HTTP response from port 8089 is missing the X-Content-Type-Options security header.
What this means
This header prevents browsers from guessing (sniffing) the content type. Without it, some attacks using malicious file uploads become easier.
What to do
Add header: X-Content-Type-Options: nosniff
Evidence: Header absent from: GET http://192.0.2.212:8089/
LOW Missing X-Frame-Options header 8089/HTTP
What was found
The HTTP response from port 8089 is missing the X-Frame-Options security header.
What this means
Without X-Frame-Options, this page could be embedded in another website's iframe. This enables clickjacking attacks.
What to do
Add header: X-Frame-Options: DENY (or SAMEORIGIN for admin panels).
Evidence: Header absent from: GET http://192.0.2.212:8089/
LOW Missing Content-Security-Policy header 8090/HTTP
What was found
The HTTP response from port 8090 is missing the Content-Security-Policy security header.
What this means
A Content Security Policy helps prevent Cross-Site Scripting (XSS) attacks by controlling which scripts and resources can load.
What to do
Implement a Content-Security-Policy header appropriate for your application.
Evidence: Header absent from: GET http://192.0.2.212:8090/
LOW Missing X-Content-Type-Options header 8090/HTTP
What was found
The HTTP response from port 8090 is missing the X-Content-Type-Options security header.
What this means
This header prevents browsers from guessing (sniffing) the content type. Without it, some attacks using malicious file uploads become easier.
What to do
Add header: X-Content-Type-Options: nosniff
Evidence: Header absent from: GET http://192.0.2.212:8090/
LOW Missing X-Frame-Options header 8090/HTTP
What was found
The HTTP response from port 8090 is missing the X-Frame-Options security header.
What this means
Without X-Frame-Options, this page could be embedded in another website's iframe. This enables clickjacking attacks.
What to do
Add header: X-Frame-Options: DENY (or SAMEORIGIN for admin panels).
Evidence: Header absent from: GET http://192.0.2.212:8090/
INFO Device identified: Router — TP-Link — Archer C7 — v3.15.1 Build 160616
What was found
Type: Router Vendor: TP-Link Model: Archer C7 Version: 3.15.1 Build 160616
What this means
Device identity determined by combining evidence from multiple sources including MAC OUI, nmap OS detection, HTTP fingerprinting, TLS certificates, SSH banners, UPnP discovery, SNMP, and port heuristics.
What to do
No action required — informational finding.
Evidence: Sources: credentials_model_index, http_fingerprint | Confidence: 81%
INFO SSH service detected: OpenSSH 10.0p2 22/SSH
What was found
SSH server identified as: SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4
What this means
An SSH service was detected. SSH is generally secure but weak algorithm choices can undermine its security.
What to do
Ensure SSH server is up-to-date and uses modern algorithm configurations.
Evidence: Banner: SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4
INFO Web interface detected: Pi-hole LabHost 80/HTTP
What was found
HTTP service on port 80: Title='Pi-hole LabHost', Server='', Status=403.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:80/ → 403 | Server:
INFO JA3S fingerprint computed on port 443 LIKELY 443/HTTPS
What was found
JA3S fingerprint computed for TLS server on port 443. No match found in signature database.
What this means
JA3S is a server-side TLS fingerprint computed from the ServerHello: TLS version, selected cipher suite, and extension types. It can identify the TLS server implementation and detect known malicious configurations.
What to do
No action required for INFO findings. If matched as malicious/suspicious, investigate the service on this port.
Evidence: JA3S: 2f9649d23227b8e19c207047c87df268
INFO TLS certificate: CN=pi.hole 443/HTTPS
What was found
Port 443 TLS certificate: CN=pi.hole, Issuer=Pi-hole, Expires=2026-07-09, Protocol=TLSv1.3, Key=EC-384.
What this means
TLS certificate details for this service.
What to do
No action required for this informational item.
Evidence: CN=pi.hole | Issuer=Pi-hole | Expires=2026-07-09, Key=EC-384
INFO Web interface detected: Pi-hole LabHost 443/HTTPS
What was found
HTTP service on port 443: Title='Pi-hole LabHost', Server='', Status=403.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET https://192.0.2.212:443/ → 403 | Server:
INFO FTP service detected: vsftpd 2.3.4 2121/FTP
What was found
FTP service running vsftpd 2.3.4 on port 2121. Banner: '220 (vsFTPd 2.3.4)'
What this means
An FTP service was detected. FTP transmits data in cleartext by default.
What to do
Consider replacing FTP with SFTP (SSH) or FTPS. Disable FTP if unused.
Evidence: Banner: 220 (vsFTPd 2.3.4)
INFO SSH service detected: OpenSSH 7.4 2222/SSH
What was found
SSH server identified as: SSH-2.0-OpenSSH_7.4
What this means
An SSH service was detected. SSH is generally secure but weak algorithm choices can undermine its security.
What to do
Ensure SSH server is up-to-date and uses modern algorithm configurations.
Evidence: Banner: SSH-2.0-OpenSSH_7.4
INFO Web interface detected: Legacy Apache Test App 5000/HTTP
What was found
HTTP service on port 5000: Title='Legacy Apache Test App', Server='Apache/2.4.49 ', Status=200.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:5000/ → 200 | Server: Apache/2.4.49
INFO Web technology detected: Apache HTTP Server 2.4.49 LIKELY 5000/HTTP
What was found
Wappalyzer signature matched: Apache HTTP Server 2.4.49 detected on port 5000.
What this means
The web interface on port 5000 appears to be running Apache HTTP Server 2.4.49. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Apache HTTP Server is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Apache HTTP Server
INFO Web technology detected: PHP 7.2.34 LIKELY 5000/HTTP
What was found
Wappalyzer signature matched: PHP 7.2.34 detected on port 5000.
What this means
The web interface on port 5000 appears to be running PHP 7.2.34. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify PHP is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): PHP
INFO Web interface detected: TP-Link Archer C7 8080/HTTP
What was found
HTTP service on port 8080: Title='TP-Link Archer C7', Server='nginx/1.14.0 ', Status=200.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:8080/ → 200 | Server: nginx/1.14.0
INFO Web technology detected: Nginx 1.14.0 LIKELY 8080/HTTP
What was found
Wappalyzer signature matched: Nginx 1.14.0 detected on port 8080.
What this means
The web interface on port 8080 appears to be running Nginx 1.14.0. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Nginx is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Nginx
INFO Web technology detected: PHP 7.2.34 LIKELY 8080/HTTP
What was found
Wappalyzer signature matched: PHP 7.2.34 detected on port 8080.
What this means
The web interface on port 8080 appears to be running PHP 7.2.34. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify PHP is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): PHP
INFO Web interface detected: Welcome to nginx! 8088/HTTP
What was found
HTTP service on port 8088: Title='Welcome to nginx!', Server='nginx/1.14.0', Status=200.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:8088/ → 200 | Server: nginx/1.14.0
INFO Web technology detected: Nginx 1.14.0 LIKELY 8088/HTTP
What was found
Wappalyzer signature matched: Nginx 1.14.0 detected on port 8088.
What this means
The web interface on port 8088 appears to be running Nginx 1.14.0. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Nginx is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Nginx
INFO Web interface detected: no title 8089/HTTP
What was found
HTTP service on port 8089: Title='', Server='Apache/2.4.49 (Unix)', Status=200.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:8089/ → 200 | Server: Apache/2.4.49 (Unix)
INFO Web technology detected: Apache HTTP Server 2.4.49 LIKELY 8089/HTTP
What was found
Wappalyzer signature matched: Apache HTTP Server 2.4.49 detected on port 8089.
What this means
The web interface on port 8089 appears to be running Apache HTTP Server 2.4.49. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Apache HTTP Server is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Apache HTTP Server
INFO Web technology detected: UNIX LIKELY 8089/HTTP
What was found
Wappalyzer signature matched: UNIX detected on port 8089.
What this means
The web interface on port 8089 appears to be running UNIX. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify UNIX is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): UNIX
INFO Web interface detected: phpinfo() 8090/HTTP
What was found
HTTP service on port 8090: Title='phpinfo()', Server='Apache/2.4.38 (Debian)', Status=200.
What this means
A web interface was found on this device.
What to do
Review this web interface to ensure it requires authentication.
Evidence: GET http://192.0.2.212:8090/ → 200 | Server: Apache/2.4.38 (Debian)
INFO Web technology detected: Apache HTTP Server 2.4.38 LIKELY 8090/HTTP
What was found
Wappalyzer signature matched: Apache HTTP Server 2.4.38 detected on port 8090.
What this means
The web interface on port 8090 appears to be running Apache HTTP Server 2.4.38. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Apache HTTP Server is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Apache HTTP Server
INFO Web technology detected: Debian LIKELY 8090/HTTP
What was found
Wappalyzer signature matched: Debian detected on port 8090.
What this means
The web interface on port 8090 appears to be running Debian. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify Debian is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): Debian
INFO Web technology detected: PHP 7.2.34 LIKELY 8090/HTTP
What was found
Wappalyzer signature matched: PHP 7.2.34 detected on port 8090.
What this means
The web interface on port 8090 appears to be running PHP 7.2.34. Knowing the exact technology stack helps identify applicable CVEs and EOL dates.
What to do
Verify PHP is up to date and check its End-of-Life status.
Evidence: Wappalyzer signature match (LIKELY): PHP
Open Ports
Port Protocol Service Software Version EOL Status
22 tcp openssh SSH-2.0-OpenSSH_10.0p2 Debian- Debian-7+deb13u4 N/A
53 tcp dnsmasq — pi-hole-v2.92rc1 N/A
80 tcp http HTTP/1.0 403 Forbidden — —
443 tcp http HTTP/1.0 403 Forbidden — —
2121 tcp vsftpd 220 (vsFTPd 2.3.4) 2.3.4 N/A
2222 tcp openssh SSH-2.0-OpenSSH_7.4 7.4 N/A
2323 tcp busybox BusyBox v1.19.4 (2012-03-15) b 1.19.4 Unknown
5000 tcp apache TP-Link 2.4.49 EOL: 2020-11-30
5555 tcp redis $468 # Server redis_version: 5.0.14 EOL: 2022-04-27
8080 tcp nginx TP-Link 1.14.0 EOL: 2019-04-23
8088 tcp nginx nginx 1.14.0 EOL: 2019-04-23
8089 tcp apache apache 2.4.49 Supported
8090 tcp apache QNAP 2.4.38 EOL: 2020-11-30
✅ Recommended Actions (by priority)