Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers

SEI Report
This report describes a test framework that the CERT/CC developed to identify systemic and other vulnerabilities in CPE routers.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2017-SR-019
DOI (Digital Object Identifier)
10.1184/R1/6584558.v1

Abstract

Customer-premises equipment (CPE)—specifically small office/home office (SOHO) routers—has become ubiquitous. CPE routers are notorious for their web interface vulnerabilities, old versions of software components with known vulnerabilities, default and hard-coded credentials, and other security issues.

This report describes a test framework that the CERT/CC developed to identify systemic and other vulnerabilities in CPE routers. It also describes the procedure the CERT/CC used in its analysis, and presents case studies and suggestions for tracking vulnerabilities in a way that encourages vendor responsiveness and increased customer awareness.

Cite This SEI Report

Land, J. (2017, July 11). Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers. (SEI Report CMU/SEI-2017-SR-019). Retrieved August 18, 2026, from https://doi.org/10.1184/R1/6584558.v1.

@techreport{land_2017,
author={Land, Joel},
title={Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers},
month={Jul},
year={2017},
number={{CMU/SEI-2017-SR-019},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/6584558.v1},
url={https://doi.org/10.1184/R1/6584558.v1},
note={Accessed: 2026-Aug-18}
}

Land, Joel. "Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers." (CMU/SEI-2017-SR-019). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, July 11, 2017. https://doi.org/10.1184/R1/6584558.v1.

J. Land, "Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-2017-SR-019, 11-Jul-2017 [Online]. Available: https://doi.org/10.1184/R1/6584558.v1. [Accessed: 18-Aug-2026].

Land, Joel. "Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers." (SEI Report CMU/SEI-2017-SR-019). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 11 Jul. 2017. https://doi.org/10.1184/R1/6584558.v1. Accessed 18 Aug. 2026.

Land, Joel. Systemic Vulnerabilities in Customer-Premises Equipment (CPE) Routers. CMU/SEI-2017-SR-019. Software Engineering Institute. 2017. DOI: 10.1184/R1/6584558.v1. https://doi.org/10.1184/R1/6584558.v1