Home Network Security Check: Find Open Ports and Vulnerabilities
Playing loads the YouTube player (Google). Or watch it on YouTube.
Find the open ports on every device in your network, see which services run behind them, check them against known vulnerabilities (CVEs) and get an action plan sorted by urgency.
Chapters
Transcript
How secure is your home network? Not the router's firewall. That one usually does its job. The question is what's running inside: a camera with an old firmware, a file share nobody switched off, a test server with an open door. In this video we'll find those spots and sort them by urgency.
As always, this is DeviceShelf's demo network, a made-up home. Every finding you'll see is one that turns up in real homes all the time.
The security check builds on the port scan. Under Settings, Scanning, Port scan and service detection is switched on by default. With every scan, DeviceShelf checks which network ports each device has open and which service answers there: a web page, SSH, file sharing, remote desktop.
An open port isn't bad in itself. Your printer needs one to print, your NAS to share files. It only becomes a risk when the wrong service is open, or an outdated one.
In the device list you can already see the open ports per device. Each little badge is one port. But reading forty-four rows of numbers isn't what anyone wants to do, so there's a report.
Open Security. At the top is the risk score, from zero to a hundred. It measures how bad the average device is, not how many devices you have, so a large network isn't punished for being large. Below twenty is green, from fifty it turns red. Twenty-seven means: a few things deserve attention.
Right below, the report says what the score covers. Here, thirty-two devices were port-scanned. For twelve more, mostly phones and devices set to quiet mode, nothing can be said, and DeviceShelf tells you so instead of counting them as safe.
Then the findings by severity: six high, nine medium, one low and four for information.
Let's go through the list. The most serious one: the Docker API on docker-host is open on port 2375 without a password. Anyone on your network can start, stop and replace containers there. That's practically full control of the machine.
Telnet on the Raspberry Pi. An ancient remote login that sends passwords as plain text. There's no good reason to have it on today.
Remote desktop on the Windows PC and screen sharing on the iMac. Handy when you use them, an open door when you don't.
And then there are known vulnerabilities. DeviceShelf compares the detected software and models with the public CVE database. The Reolink camera matches a vulnerability that lets someone on your network read its configuration without logging in. The CVE number links to the official entry.
Below that, medium findings: file sharing over SMB on the NAS and the computers, SNMP on the switch and the printer, an expired certificate on the camera. At home that's often fine, but you should know about it.
The information entries list every camera, so you can check that each one is really yours.
Twenty findings are a lot. Which ones first? The AI security advisor turns the list into a plan. Click Advise. The findings go to the AI provider you chose in the settings, or to a local model on your own computer, and come back as steps sorted by urgency.
First, close the Docker API. Second, switch off Telnet and update SSH on the Pi. Third, new firmware for the camera. Then remote desktop, and finally keep file sharing on the trusted part of the network. Each step names the device and what to do.
One more check on this page: the router password check. It tries the well-known factory passwords on your own router, such as admin and admin. It's off until you confirm it, and it only ever talks to your own gateway.
Now let's look at one device in detail. Open the Raspberry Pi and go to Security. Here are its open ports with the service on each, the known vulnerabilities and the services it announces on the network.
Under Tools, Check vulnerabilities hands exactly this device's findings to the AI and asks for an assessment.
The answer: high risk, because of Telnet and the OpenSSH vulnerability, and what to do about it. Disable Telnet, update OpenSSH, and only allow logins with a key.
Next to it, Default logins tries the factory passwords on this one device. And on devices with an encrypted web page you also get a TLS grade, which rates how well that encryption is set up.
And under Monitoring, the port scan setting. On every scan is the default, so a newly opened port is reported within minutes. Once a day is gentler on small devices, and never puts a device into quiet mode. Some cheap smart plugs crash when they're scanned, and this is the switch for them.
Security isn't a one-off check. The timeline shows when the Docker port on docker-host opened: today, at twelve forty. With alerts switched on, you would have heard about it the moment it happened, by desktop notification, e-mail or webhook.
Under Settings, Checks, DeviceShelf can also watch your TLS certificates and domain names and warn you before they expire, so the expired certificate on the camera never happens again.
If you'd rather ask than click through lists, there's the AI Cockpit. Type a question in plain language, for example: where do I have security gaps? The assistant gets a summary of every device and answers with the concrete spots.
Like everything with AI in DeviceShelf, the cockpit is optional, off until you set it up, and works with a local model if you don't want your device list to leave the house.
So: keep the port scan on, open the security report and start at the top, with remote control that needs no password and logins in plain text. Let the advisor sort the rest. And leave alerts on, so you hear about a newly opened port the same day.
That's the third question in this series. If you missed them, the other two videos show how to find every device on your network and which one is using your bandwidth. DeviceShelf runs on Mac, Windows and Linux, at deviceshelf dot app.