RedCyferBusiness technology Call (870) 876-3016

Back to Writing

Your printer is on the internet

Picture a small office that calls because their printer has started sending spam. Not from the office email account, from the printer itself. The device has a web interface, an SMTP relay feature that was enabled by default, and a public IP address that it requested from the router without anyone noticing. The password is still admin/admin. Someone found it, logged in, and configured it to relay mail for a spam campaign. The office had no idea the printer was reachable from the internet. They did not forward any ports manually. The printer did it by itself using UPnP.

Universal Plug and Play is a protocol that allows devices on your network to ask your router to open ports and forward traffic to them. The idea is convenience. A printer, security camera, or DVR can configure its own port forwarding so that a mobile app or remote access feature works without the user needing to log into the router. The problem is that UPnP does not ask permission and does not verify that the request is legitimate. Any device on the network can open any port, and most consumer and small business routers ship with UPnP enabled.

The result is devices exposed to the public internet with default credentials, unpatched firmware, and web interfaces that were never designed to be publicly accessible. Printers with administrative consoles. Cameras with live feeds. DVRs with full access to recorded video. The owners do not know the ports are open because they did not open them. The devices did it automatically, and there is no notification.

How to see what is exposed

Log into your router and look for a UPnP status page or port forwarding list. Most routers have a section that shows active port forwards, including those created by UPnP. Look for entries you did not create. Common ports are 80, 443, 8080, 9000, 554, and high random ports above 49152. If you see a forward pointing to an internal IP address you do not recognize, check what device has that IP. The router's DHCP client list or attached devices page will show the device name or MAC address.

From outside your network, use a port scanning service or ask someone on a different network to browse to your public IP address on the ports you found. If a login page appears, the device is exposed. If the login page is for a printer, camera, or DVR, and you did not intentionally expose it, that is a UPnP forward.

The other check is to search for your public IP address on Shodan, a search engine for internet-connected devices. Shodan scans the internet continuously and indexes what it finds. If your printer or camera is exposed, Shodan has probably already found it. A search will show what ports are open and what services are running. If you see your printer model or camera brand, it is public.

Turn off UPnP without breaking anything

The fix is to disable UPnP on the router. The setting is usually under advanced settings, NAT, or firewall. Turn it off. Existing UPnP forwards may remain in the port forwarding table even after UPnP is disabled, so delete any forwards you did not create manually.

The concern is always that disabling UPnP will break something that depends on it. In a small business environment, that is rarely the case. Most legitimate services either work without port forwarding or require manual configuration anyway. Remote desktop, VPN, and hosted applications do not use UPnP. Video conferencing and VoIP work without it if the router supports SIP ALG or if the service uses a relay. The devices that depend on UPnP are usually consumer-grade cameras, DVRs, and printers that expect to be remotely accessible without configuration.

If you disable UPnP and something stops working, the correct fix is not to re-enable UPnP. The correct fix is to configure that service properly. If you need remote access to a camera system, put it behind a VPN or use the manufacturer's cloud service if it is reputable. If you need a printer accessible from outside, do not expose it directly. Use a print server or remote desktop. If a device cannot function without UPnP and cannot be configured manually, replace it with a device that can.

Where this sits in what RedCyfer does

Network segmentation and firewall review are part of managed network work. For clients on the Care plan, this is part of the quarterly network check. For one-time network projects, it is part of the initial audit. The goal is a network where nothing is exposed unless you decided to expose it, and where devices that do not need internet access do not have it. UPnP is off, port forwards are documented, and cameras and printers are on a segment that cannot reach the internet or the rest of the network without a specific rule. That is not exotic. It is just configured instead of default.

Want this looked at for your own business?

Tell us what is going on and Chris will reply. Call (870) 876-3016, text (870) 641-5054, or send a note.

Talk to Chris