I finally started getting ShadowServer reports which are nice.
One thing I notice is that about 5% of customers still have routers with SSDP (the discovery protocol for UPnP) exposed on the WAN side. This despite the fact that I scanned the network earlier this year and sent notices to every single customer with this vulnerability. It tells me very few did anything about it. Most of these are DLink DIR-615 routers, and except for the very last version of that router, there is no FW update, their only solution is to disable UPnP in the menus. Apparently that's too difficult for customers.
My question: is this serious enough to worry about? Should I just wait for those DLink routers (or their owners) to die?
I guess another solution would be to block ports 1900/2049/5783 but these might be legitimately in use as ephemeral ports and I don't like blocking high numbered ports.
