Wartiva Security Controls

Device Exposure: 7 Checks

Wartiva's Device Exposure controls: devices that put your network at risk: ports exposed to the public internet, and equipment from vendors prohibited under Section 889 of the U.S. National Defense Authorization Act (NDAA), such as Huawei, ZTE, Hikvision, Dahua, and Hytera, or otherwise untrusted.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 7 checks on this page

Services a device exposes to the public internet

Ensure Devices Do Not Have Publicly Exposed Ports

Medium severity · Wartiva Security Controls · Device Exposure

Finding: This device has one or more ports exposed to the public internet.

This rule finds devices with an open port that is reachable from the public internet. This rule fails for each such device.

Rationale: Every internet-reachable service is attack surface; unnecessary public exposure increases the risk of exploitation.

Impact: Publicly exposed ports can be scanned, brute-forced, or exploited by anyone on the internet.

Remediation

Review the device's internet-exposed ports. Close or firewall any service that doesn't need to be publicly reachable, place required services behind a VPN or authenticating reverse proxy, and restrict inbound access at the network perimeter.

Framework mappings
  • CIS Controls v8: 12.2 Establish and Maintain a Secure Network Architecture
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CP-2 Contingency Plan; CP-6 Alternate Storage Site; CP-7 Alternate Processing Site; PL-8 Security and Privacy Architectures; PM-7 Enterprise Architecture; SA-8 Security and Privacy Engineering Principles; SC-3 Security Function Isolation; SC-7 Boundary Protection; SI-4 System Monitoring
  • NIST SP 800-171 Rev. 2: 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; 3.4.6 Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities; 3.13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems; 3.13.5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks
  • CMMC 2.0 Level 1: SC.L1-b.1.xi Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks
  • CMMC 2.0 Level 2: AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; CM.L2-3.4.6 Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities; SC.L2-3.13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems; SC.L2-3.13.5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 1.3.2 Limit outbound CDE traffic to what is necessary, denying the rest; 1.3.3 Separate every wireless network from the CDE using NSCs, denying by default; 1.4.4 Prevent direct untrusted network access to systems storing cardholder data; 7.1 Governance processes for need-to-know access restriction are established; 7.2.5.1 Periodically recertify privileges held by application and system-level accounts; 11.4.5 Annually pen test segmentation controls that isolate the CDE
Risks
External Exposure, External Attack Surface
MITRE ATT&CK tactic
Reconnaissance (TA0043)

A device made by a vendor that cannot be trusted (e.g. one that ships factory backdoors)

Ensure No United States NDAA Section 889 Prohibited Dahua Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A Dahua device, prohibited under United States NDAA Section 889, is present.

This rule inspects a discovered network device's resolved manufacturer and hardware address (MAC). This rule fails when the device is made by Zhejiang Dahua Technology, whose video-surveillance equipment is prohibited under Section 889 of the United States National Defense Authorization Act (NDAA) and listed on the United States Federal Communications Commission (FCC) Covered List.

Rationale: Section 889 is a United States federal law that bars U.S. government agencies and contractors from procuring or using video-surveillance equipment from this vendor, which the U.S. government considers a national-security and espionage risk. The restriction attaches to the equipment whatever brand is printed on the housing (Dahua is a prolific OEM). The authoritative, continuously updated inventory is the U.S. FCC Covered List: fcc.gov/supplychain/coveredlist. This is a United States legal designation; organizations outside the U.S. may weigh it differently, but the underlying supply-chain risk applies anywhere. Detection is by the device's resolved manufacturer, derived from its MAC OUI.

Impact: A prohibited IP camera or recorder can leak video, phone home to external infrastructure, or serve as a foothold on the internal network, and its presence can breach U.S. federal contractual and regulatory obligations.

Remediation

Locate the device by its MAC address and remove it from any network subject to United States NDAA Section 889 (for example, networks serving U.S. federal agencies or contractors). Confirm the device against the U.S. FCC Covered List (fcc.gov/supplychain/coveredlist), replace it with a camera or recorder from a trusted vendor, and review logs for anomalous outbound connections. Outside the United States, assess the device against your own regulatory and risk requirements.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure No United States NDAA Section 889 Prohibited Hikvision Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A Hikvision device, prohibited under United States NDAA Section 889, is present.

This rule inspects a discovered network device's resolved manufacturer and hardware address (MAC). This rule fails when the device is made by Hangzhou Hikvision Digital Technology, whose video-surveillance equipment is prohibited under Section 889 of the United States National Defense Authorization Act (NDAA) and listed on the United States Federal Communications Commission (FCC) Covered List.

Rationale: Section 889 is a United States federal law that bars U.S. government agencies and contractors from procuring or using video-surveillance equipment from this vendor, which the U.S. government considers a national-security and espionage risk. The restriction attaches to the equipment whatever brand is printed on the housing (Hikvision is a prolific OEM). The authoritative, continuously updated inventory is the U.S. FCC Covered List: fcc.gov/supplychain/coveredlist. This is a United States legal designation; organizations outside the U.S. may weigh it differently, but the underlying supply-chain risk applies anywhere. Detection is by the device's resolved manufacturer, derived from its MAC OUI.

Impact: A prohibited IP camera or recorder can leak video, phone home to external infrastructure, or serve as a foothold on the internal network, and its presence can breach U.S. federal contractual and regulatory obligations.

Remediation

Locate the device by its MAC address and remove it from any network subject to United States NDAA Section 889 (for example, networks serving U.S. federal agencies or contractors). Confirm the device against the U.S. FCC Covered List (fcc.gov/supplychain/coveredlist), replace it with a camera or recorder from a trusted vendor, and review logs for anomalous outbound connections. Outside the United States, assess the device against your own regulatory and risk requirements.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure No United States NDAA Section 889 Prohibited Huawei Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A Huawei device, prohibited under United States NDAA Section 889, is present.

This rule inspects a discovered network device's resolved manufacturer and hardware address (MAC). This rule fails when the device is made by Huawei Technologies (including its HiSilicon components), whose equipment is prohibited under Section 889 of the United States National Defense Authorization Act (NDAA) and listed on the United States Federal Communications Commission (FCC) Covered List.

Rationale: Section 889 is a United States federal law that bars U.S. government agencies and contractors from procuring or using telecommunications and networking equipment from this vendor, which the U.S. government considers a national-security and espionage risk. Section 889 reaches down to the component level, including Huawei's HiSilicon processors. The authoritative, continuously updated inventory is the U.S. FCC Covered List: fcc.gov/supplychain/coveredlist. This is a United States legal designation; organizations outside the U.S. may weigh it differently, but the underlying supply-chain risk applies anywhere. Detection is by the device's resolved manufacturer, derived from its MAC OUI.

Impact: Prohibited networking equipment on core traffic paths can enable interception, backdoored firmware, or data exfiltration, and its presence can breach U.S. federal contractual and regulatory obligations.

Remediation

Locate the device by its MAC address and remove it from any network subject to United States NDAA Section 889 (for example, networks serving U.S. federal agencies or contractors). Confirm the device against the U.S. FCC Covered List (fcc.gov/supplychain/coveredlist), replace it with equipment from a trusted vendor, and review logs for anomalous outbound connections. Outside the United States, assess the device against your own regulatory and risk requirements.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure No United States NDAA Section 889 Prohibited Hytera Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A Hytera device, prohibited under United States NDAA Section 889, is present.

This rule inspects a discovered network device's resolved manufacturer and hardware address (MAC). This rule fails when the device is made by Hytera Communications, whose equipment is prohibited under Section 889 of the United States National Defense Authorization Act (NDAA) and listed on the United States Federal Communications Commission (FCC) Covered List.

Rationale: Section 889 is a United States federal law that bars U.S. government agencies and contractors from procuring or using telecommunications equipment from this vendor, which the U.S. government considers a national-security and espionage risk. The authoritative, continuously updated inventory is the U.S. FCC Covered List: fcc.gov/supplychain/coveredlist. This is a United States legal designation; organizations outside the U.S. may weigh it differently, but the underlying supply-chain risk applies anywhere. Detection is by the device's resolved manufacturer, derived from its MAC OUI.

Impact: Prohibited land-mobile-radio or telecommunications equipment can enable interception of communications or data exfiltration, and its presence can breach U.S. federal contractual and regulatory obligations.

Remediation

Locate the device by its MAC address and remove it from any network subject to United States NDAA Section 889 (for example, networks serving U.S. federal agencies or contractors). Confirm the device against the U.S. FCC Covered List (fcc.gov/supplychain/coveredlist), replace it with equipment from a trusted vendor, and review logs for anomalous outbound connections. Outside the United States, assess the device against your own regulatory and risk requirements.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure No United States NDAA Section 889 Prohibited ZTE Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A ZTE device, prohibited under United States NDAA Section 889, is present.

This rule inspects a discovered network device's resolved manufacturer and hardware address (MAC). This rule fails when the device is made by ZTE Corporation, whose equipment is prohibited under Section 889 of the United States National Defense Authorization Act (NDAA) and listed on the United States Federal Communications Commission (FCC) Covered List.

Rationale: Section 889 is a United States federal law that bars U.S. government agencies and contractors from procuring or using telecommunications and networking equipment from this vendor, which the U.S. government considers a national-security and espionage risk. The authoritative, continuously updated inventory is the U.S. FCC Covered List: fcc.gov/supplychain/coveredlist. This is a United States legal designation; organizations outside the U.S. may weigh it differently, but the underlying supply-chain risk applies anywhere. Detection is by the device's resolved manufacturer, derived from its MAC OUI.

Impact: Prohibited networking equipment on core traffic paths can enable interception, backdoored firmware, or data exfiltration, and its presence can breach U.S. federal contractual and regulatory obligations.

Remediation

Locate the device by its MAC address and remove it from any network subject to United States NDAA Section 889 (for example, networks serving U.S. federal agencies or contractors). Confirm the device against the U.S. FCC Covered List (fcc.gov/supplychain/coveredlist), replace it with equipment from a trusted vendor, and review logs for anomalous outbound connections. Outside the United States, assess the device against your own regulatory and risk requirements.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risk
High Profile Threat
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure No Untrusted-Vendor (ZBT / Shenzhen Zhibotong) Devices Are Present

High severity · Wartiva Security Controls · Device Exposure

Finding: A network device made by ZBT (Shenzhen Zhibotong) — a vendor that ships factory backdoors — is present.

This rule inspects a discovered network device's hardware address (MAC) and resolved manufacturer. This rule fails when the device is manufactured by ZBT (Shenzhen Zhibotong Electronics, also branded Zbtlink), identified by its IEEE OUI prefix (78:A3:51 or F8:5E:3C) or its resolved manufacturer name.

Rationale: ZBT ships routers with factory-installed backdoors across its product line — ENDLESSDOORS (CVE-2026-66747), SPEAKINGSTONE (CVE-2026-74232), and DARKLANTERN (CVE-2026-74233) — that grant unauthenticated remote code execution as root and beacon to command-and-control infrastructure at boot. Because the implants are present from the factory and no trustworthy fix exists, any device from this vendor is treated as untrusted. Detection is by MAC OUI because these devices rarely advertise their model over any protocol the platform observes.

Impact: A ZBT device on the network gives an attacker a persistent, root-level foothold reachable through its C2 channel, from which it can intercept traffic, pivot to other hosts, and exfiltrate data.

Remediation

Locate the device using its reported MAC address and remove it from the network. ZBT (Shenzhen Zhibotong / Zbtlink) hardware contains factory-installed backdoors with no trustworthy vendor fix; do not attempt to patch it. Replace it with equipment from a trusted vendor, and review network logs for outbound connections to unfamiliar hosts that may indicate command-and-control activity.

Framework mappings
  • CIS Controls v8: 1.2 Address Unauthorized Assets
  • NIST SP 800-53 Rev. 5: CM-8 System Component Inventory
  • PCI DSS v4.0.1: 11.2.1 Scan for wireless access points quarterly and identify rogue devices
Risks
Vulnerability, High Profile Threat
MITRE ATT&CK tactics
Persistence (TA0003), Command and Control / Exfiltration (TA0011, TA0010)