Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TCP-32764 — some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G. | Kitploit
Tools/GitHubGitHub/elvanderb/tcp-32764
Embedded Systems SecurityVulnerability AnalysisExploitationInformation GatheringNetwork SecurityRed TeamingCurated Resources
GitHubelvanderb/tcp-32764

TCP-32764

some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G.

View Repository
1.3k216157 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

I WILL NOT MANUALLY UPDATE THIS REPOSITORY ANYMORE

If you want to add a router in the list, please make a pull-request, also remember to USE THE POC and paste the result in your pull-request. Telnet clients and other solutions may not be relevant (some false negative / positive reported).

Some random code/data about the backdoor I found in my Linksys WAG200G (TCP/32764).

The backdoor may be present in other hardware, I'll update this readme accordingly. :)

Possible fix :

  • if it's listening on the internet: add a firewall rule in the web UI (@domainzero)
  • it also seems to work on the LAN side. (issue 35)
  • but apparently, not for every body (issue 57) so use the PoC again after adding the rule to make sure the firewall does its job.
  • install an open source firmware (for example OpenWRT or Tomato) this is NOT magical, OpenWAG200 is vuln: http://sourceforge.net/projects/openwag200/files/OpenWAG200/1.4/
  • kill the backdoor after each reboot (issue 61 & TCP-32764-First-Aid)
  • use this alternative firmware: amod (thank you pidocchio and nremond)
  • redirect the port traffic in your router firewall to a local unused IP and done ([@osisecurite])

Probable source of the backdoor:

  • SerComm https://news.ycombinator.com/item?id=6998258 (nice finding :) )
  • Confirmed by a header (socket_header.h) in cisco gpl sources (thank you Andreas Fett!)

Backdoor LISTENING ON THE INTERNET confirmed in :

  • Linksys WAG120N (@p_w999)
  • Netgear DG834B V5.01.14 (@domainzero)
  • Netgear DGN2000 1.1.1, 1.1.11.0, 1.3.10.0, 1.3.11.0, 1.3.12.0 (issue 44)
  • Netgear WPNT834 (issue 79)
  • OpenWAG200 maybe a little bit TOO open ;) (issue 49)

Backdoor confirmed in:

  • Cisco RVS4000 fwv 2.0.3.2 & 1.3.0.5 (issue 57)
  • Cisco WAP4410N (issue 11)
  • Cisco WRVS4400N
  • Cisco WRVS4400N (issue 36)
  • Diamond DSL642WLG / SerComm IP806Gx v2 TI (https://news.ycombinator.com/item?id=6998682)
  • LevelOne WBR3460B (http://www.securityfocus.com/archive/101/507219/30/0/threaded)
  • Linksys RVS4000 Firmware V1.3.3.5 (issue 55)
  • Linksys WAG120N (issue 58)
  • Linksys WAG160n v1 and v2 (@xxchinasaurxx @saltspork)
  • Linksys WAG200G
  • Linksys WAG320N (http://zaufanatrzeciastrona.pl/post/smieszna-tylna-furtka-w-ruterach-linksysa-i-prawdopodobnie-netgeara/)
  • Linksys WAG54G2 (@_xistence)
  • Linksys WAG54GS (@henkka7)
  • Linksys WRT350N v2 fw 2.00.19 (issue 39)
  • Linksys WRT300N fw 2.00.17 (issue 34)
  • Netgear DG834[∅, GB, N, PN, GT] version < 5 (issue 19 & issue 25 & issue 62 & jd & Burn2 Dev)
  • Netgear DGN1000 (don't know if there is a difference with the others N150 ones... issue 27)
  • Netgear DGN1000[B] N150 (issue 3)
  • Netgear DGN2000B (issue 26)
  • Netgear DGN3500 (issue 13)
  • Netgear DGND3300 (issue 56)
  • Netgear DGND3300Bv2 fwv 2.1.00.53_1.00.53GR (issue 59)
  • Netgear DM111Pv2 (@eguaj)
  • Netgear JNR3210 (issue 37)

Backdoor may be present in:

  • all SerComm manufactured devices (https://news.ycombinator.com/item?id=6998258)
  • Linksys WAG160N (http://zaufanatrzeciastrona.pl/post/smieszna-tylna-furtka-w-ruterach-linksysa-i-prawdopodobnie-netgeara/)
  • Netgear DG934 probability: probability: 99.99% (http://codeinsecurity.wordpress.com/category/reverse-engineering/)
  • Netgear WG602, WGR614 (v3 doesn't work, maybe others...) (http://zaufanatrzeciastrona.pl/post/smieszna-tylna-furtka-w-ruterach-linksysa-i-prawdopodobnie-netgeara/)
Download Tool