It usually stands in the hallway. Or in the cellar. A flat, warm-running device with blinking LEDs that the provider brought along when the contract was signed. You plug it in, join the Wi-Fi, forget it. Years later it is still running — same firmware, same password, same gaps as on day one.

Nobody in the household knows what happens inside it. Nobody can find out. The device that guards the crossing between the public internet and everything that matters to you — banking traffic, family devices, cameras, the VPN tunnel into the home office — is a black box. And the track record of these black boxes is, frankly, catastrophic.

A chronicle of failure

You do not have to dig long to find hair-raising stories. The history of customer premises equipment — the so-called CPE — is a sequence of scandals that each briefly caused alarm and were then forgotten by the next device generation.

In 2016 the Mirai worm took over hundreds of thousands of devices, simply by trying factory logins and default passwords that nobody had changed. Routers were among them. Those same devices were then fielded as an army against critical infrastructure — the attack on the DNS provider Dyn took down Twitter, Reddit, Netflix and GitHub simultaneously.

In 2018 VPNFilter surfaced. Not a script-kiddie coincidence, but a professional, state-attributed attacker. Affected were SOHO routers from Linksys, MikroTik, Netgear, TP-Link and QNAP. Estimates spoke of more than half a million infected devices across 54 countries. The malware survived reboots, could destroy firmware, intercept traffic, harvest credentials and turn the devices into anonymous relays for further attacks. The FBI confiscated a control domain. The message was unmistakable: anyone operating a consumer router is potentially operating a soldier under someone else’s orders.

Before and after: Misfortune Cookie (2014), a flaw in the RomPager software embedded in countless ISP gateways, leaving more than twelve million devices remotely rootable. The TheMoon worm against Linksys. TR-069/CWMP interfaces that let providers manage devices remotely — and whose opening stood wide open to anyone who found the interface. UPnP, which automatically punched ports outward and made millions of networks attackable. FTC proceedings against ASUS (2016, a twenty-year audit mandate) and D-Link (complaint 2017), because marketing promised “Advanced Security” while the devices lacked elementary protective functions.

And that is only the accidental side.

Accidental holes — and deliberate backdoors

Now it gets uncomfortable. Not every vulnerability is an accident.

In 2013 a researcher found a hidden service on TCP port 32764 in dozens of router models from the manufacturer Sercomm — devices sold under the brands Linksys, Netgear, Cisco, Diamond and others, an estimated two million units. The service accepted cleartext commands with root privileges. No authentication. Built-in remote control, simply forgotten to be switched off. Reports followed about hardcoded accounts in assorted consumer and small-business devices, about debug interfaces left in production images, about update channels that were signed yet opaque.

On top of that come political warnings that cannot be dismissed. The United States, Australia and several European states have banned equipment from certain manufacturers out of critical infrastructure — citing possible state influence. Strictly forensically proven this is not always. But the question of whether a device has a door at the back whose key only the manufacturer — and perhaps a state — possesses cannot be answered with closed firmware. Period. And that is precisely the problem.

With disclosed code you can search. With closed firmware you can only hope. Hope that there is no second port 32764. Hope that the update image really contains only what the changelog names. Hope that nobody left an emergency access that nobody documented. Building security on hope is not a strategy. It is gambling.

Why “it’s just the router” is lethal

Again and again I hear: “But only private devices hang off that router.”

That is exactly the thinking error. The router is not some peripheral device at the edge. It is the door through which everything passes. Every email, every banking session, every video call with the accountant, every login into the corporate network from the home office — all of it streams past this device. Whoever controls the router controls the entire data flow. They can bend DNS resolution and redirect banking sites to forged servers. They can inject certificates and silently break encryption. They can launch lateral movement into the internal network — to the NAS, to cameras, to unprotected smart-home gadgets, to workstations with corporate access. And they can use the whole thing as a beachhead for attacks that have nothing to do with the owner, but with the device serving as a relay for botnets.

In a corporate context the CPE is the edge of the entire organisation. A small branch office with a poorly maintained provider router is not an isolated risk — it is the way in.

New enemies, old devices

The situation is tightening. Two developments make the status quo more urgent.

First: edge devices have become the preferred target of state-aligned attackers. SOHO routers sit under little scrutiny, are rarely updated and offer long dwell time. Exactly what persistence-oriented operators seek. The major campaigns of recent years aimed not at data centres but at the unmanned boxes at the network edge.

Second: the tooling to find and exploit vulnerabilities is becoming mass-market. Automated scanners, AI-assisted exploit generation, autonomous offensive systems — the barrier drops. Whoever once needed months to analyse a firmware now gets pointers to anomalies in hours. Defence meanwhile keeps waiting for the vendor patch that often never arrives. Many models simply stop receiving updates after two or three years — formally end-of-support, effectively a death certificate.

This imbalance is structural. The attacker has to win once. The defender has to win every time — with a black box they can neither read nor patch.

The sensible alternatives

They exist. And they are not exotic. Four families of systems form the only rational answer once you take control of the network crossing seriously.

OpenWrt. Born from exactly the moment in 2003 when the Linksys WRT54G, Linux firmware included, had to be released under the GPL — a story that shows what enforced copyleft can unleash. OpenWrt replaces the firmware of supported consumer routers with an open Linux system. Configuration readable, package manager included, regular updates, the LuCI web interface. If you already have suitable hardware, you rescue the investment and gain a device you understand.

OPNsense. FreeBSD-based, emerging in 2014 as a fork of pfSense, with a more modern interface, hard default configuration and an active release cadence. Ships IDS/IPS via Suricata, WireGuard and IPsec, certificate management and logging on board. Runs on x86 mini-appliances or virtual machines. For many the most sensible entry into a “real” firewall system.

pfSense. Likewise FreeBSD, the older, widely deployed relative. Mature, productive in countless SME environments, with high availability, multi-WAN and extensive documentation. Those seeking a stable, battle-tested system find it here.

Manual firewall on Linux or BSD. For everyone who wants full control: nftables on the Linux kernel (successor to iptables, part of netfilter) or pf on OpenBSD — configured on a hardened host that doubles as a router. Rule set versioned as code, auditable, reproducible. Maximum transparency, maximum responsibility. Whoever takes this route understands every packet that passes.

These systems are the sensible alternative because they are open. Because you can read the rule set. Because updates arrive, because a community stands behind them. Because you do not have to hope — you can know.

It is easier than most think

The objection goes: “That is for professionals. Far too complicated for an ordinary user.”

It is not. The barrier to entry is lower than its reputation.

A decommissioned mini PC, a thin client from an office clearance, a small x86 appliance for a hundred euros — all become serious firewalls once OPNsense or pfSense runs on them. A Raspberry Pi suffices for small home networks. Anyone who already owns a compatible consumer router flashes OpenWrt in ten minutes and keeps the hardware. An inexpensive managed switch with VLAN capability segments the network into guest, IoT and work zones — no witchcraft involved.

And you do not have to type. LuCI, the OPNsense and pfSense web interfaces guide you through setup, rules, VPN tunnels. The command line is optional — those who want it gain precision; those who do not still reach the goal. One weekend of learning, solid documentation, a helpful community. After that you operate a system you understand — for years, often decades.

Why the wider public should seriously consider it

Security must not remain a luxury for specialists. The factory defaults that providers ship are not optimised for defence but for as few support calls as possible. That is not ill will — it is an economic incentive that structurally works against the user.

The cost of a break-in — identity theft, drained accounts, compromised cameras, children’s data in stranger’s hands, a company breached through the home office — bears no relation to a weekend’s effort. And collectively: as long as millions of routers remain usable as botnet soldiers, we are all affected, even those well secured themselves. Digital hygiene is not a private matter. Whoever hardens their router protects not only themselves — they remove a potential soldier from an army pointed at others.

When it scales: central manageability

At a small scope a single device suffices. Anyone operating several sites — a mid-sized company, an organisation with branches, a residential facility with multiple segments — needs more: a fleet of firewalls governed jointly.

This is exactly where OpenWrt, OPNsense and pfSense unfold their second strength. Configuration as code, rolled out via Ansible or Puppet. Central logging in Graylog or Wazuh. Monitoring through Prometheus, Grafana or LibreNMS. Meshed VPNs over WireGuard or IPsec linking the sites. Zero-touch provisioning that folds a new device at a remote site into the existing structure on first boot. Coordinated incident response across all nodes. This is no dark magic — it is established practice. Try that with a pile of mismatched provider boxes.

What this means for libcom.de

Here it gets concrete. Firewall systems and network security are a specialist field of libcom.de. For more than two decades I — Jochen Demmer — have planned, built and operated open firewall and routing solutions, from a hardened single device to a centrally administered fleet spanning multiple sites.

Important: these are not off-the-shelf solutions. Every environment has its own requirements — its own topology, its own threat landscape, its own compliance constraints, its own trajectory of growth. A one-size-fits-all solution protects just as little as the provider router it is meant to replace. That is why the work does not begin with a product catalogue but with an inventory: what runs, what does it protect, what does it not, and where should it develop?

For smaller environments that often means: a hardened OpenWrt or OPNsense device, cleanly segmented, documented, handed over. For larger ones: a distributed firewall system with central administration, config-as-code, monitoring, alerting and a clear migration path. We plan, implement, document and train — and we do not remain the bottleneck. Those who leave us can keep the system running because it is understandable, standardised and traceable.

If you wonder whether your current network crossing is still contemporary, or if you seek a solution that reaches beyond the next provider box: write to contact@libcom.de. We take an honest inventory. Without sales pressure. With a view to what lasts long-term.


The router at the edge of your network is not a neutral device. It is the spot where everything passes through — and where the least attention is paid. It is time to change that.

Open firewall systems are not a measure for specialists. They are the sensible answer to a black box that went unquestioned for far too long.

Note: This article offers general orientation and does not replace an individual security review. Statements about specific products or manufacturers are based on publicly known incidents; all information is provided without warranty.