Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 DLink DIR-X3060Z Router Speedtests & Tips, Oh. So. Free.

views
     
kwss
post Aug 19 2025, 09:03 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(JON97 @ Aug 19 2025, 02:47 PM)
Randomly decided to check my DIR-X3060Z (AX3000) logs and came across my public IP is open on 80 and 443.

Remote management - disabled
Port Forwarding - None
Remote ManageMent Status
- Onu Inform to ITMS - Unreported(Terminal is starting)
- ITMS Access to Onu - CPE Connection Uninitialized
Firmware - DIR-X3060Z_220522_1.0.2

user posted image

Here is the error log:
Does anyone know how to fix this? Or the only way is to get a better router since this is TM locked?
*
Telltale sign your router is now part of a botnet:
Management interface still accessible from internet when remote management is disabled.
You ran out of file descriptor. Either too many open file or socket. I suspect it's the latter since that's what botnet mostly do.

Unless you have the firmware, which you don't because no ISP publish firmware for their rubbish...

Scrap this device and buy a new one.

EDIT:
You test and open the web UI from another telco like mobile data right?

This post has been edited by kwss: Aug 19 2025, 09:08 PM
kwss
post Aug 19 2025, 11:21 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(JON97 @ Aug 19 2025, 11:10 PM)
You test and open the web UI from another telco like mobile data right?
- Yes correct.

Yea that's the thing. I doubt they will even want to give me the firmware to update it. Will try with a second router in the mean time.
*
Then I can say with certainty your router is a bot.
You need to keep your router firmware updated.
Disable all remote management.
Change all default password.

The thing with TM router is that even if you disable TR069, VLAN 209 is still terminated in both the ONU and the router. So technically your device is still discoverable remotely.

To make matter worst, the TM firmware will allow ACS unrestricted access, meaning it's possible for VLAN 209 to jump into your LAN.
kwss
post Aug 20 2025, 12:56 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(JON97 @ Aug 20 2025, 12:46 AM)
The thing with TM router is that even if you disable TR069, VLAN 209 is still terminated in both the ONU and the router. So technically your device is still discoverable remotely.

To make matter worst, the TM firmware will allow ACS unrestricted access, meaning it's possible for VLAN 209 to jump into your LAN.


- Looks like I missed out on this. It seems so, this is the case. I tired with my other mesh router (Which I didn't use) and its the same issue. Public IP exposed.

Unifi won't give the firmware, and dont see anyone share any recent firmware. So looks like a new router it is.

Update: Not sure if DIR-X3060 supports OpenWrt
*
I want to be very clear: No amount of firmware update will help if you are using TM hardware.

The boa web server is forever vulnerable. The ACS and VLAN209 is forever there.

Most importantly, their new firmware don't fix security issue or what not. They only fix compatibility issue.

If security is a concern, do not plug in anything from TM into your network.

 

Change to:
| Lo-Fi Version
0.0163sec    0.43    6 queries    GZIP Disabled
Time is now: 6th December 2025 - 07:14 PM