Windows 10 / 11

Windows Network Vulnerability Scanning — ShieldGuard NET

Scans routers and devices on your home private network for known vulnerabilities (CVEs) and end-of-life models. A safety-first tool designed so it cannot scan other people's networks.

A key design decision: scan scope is restricted. ShieldGuard NET only targets the private network (RFC 1918: 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12) that this PC is connected to. Neither the UI nor the CLI provides a way to specify an arbitrary IP address or subnet. This isn't a missing feature — it's a deliberate safety decision. For a consumer product, we prioritized structurally preventing a buyer from accidentally (or intentionally) scanning someone else's network.
WHAT IT DOES

Safe, read-only scanning.

Known Vulnerability (CVE) Matching

Cross-references detected device vendors and models against a database of known vulnerabilities sourced from the CISA Known Exploited Vulnerabilities (KEV) catalog. See our explainer article for how CVEs and the KEV catalog work.

CISA KEVCVE Matching

TCP Port Scanning

Connect scans only. No SYN scans or raw sockets are used.

HTTP Banner Grabbing

Vendor and model are inferred using read-only GET requests only.

End-of-Life Detection

Flags devices whose manufacturer support has ended and suggests replacement.

WHAT IT DOESN'T DO

What it doesn't do (by design)

  • Never attempts to exploit vulnerabilities
  • Never attempts credential guessing or brute-forcing
  • Cannot scan networks other than your own (a deliberate restriction)
  • Does not retrieve exact firmware versions — since detection relies on inferring the model from an HTTP banner rather than SNMP or vendor-specific APIs, model and vulnerability matches are for reference only
SPECIFICATIONS

Specifications

Supported OSWindows 10 / 11 (64-bit)
Scan scopeOnly the private network this PC is connected to (RFC 1918)
Vulnerability dataCISA KEV catalog, NVD public data
ImplementationRust
Price$6.25 (one-time, no subscription)
LicenseOne license per PC
Base engineRedesigned for Windows and consumer use from the open-source router-cve-audit (MIT)
FAQ

Frequently asked questions

Can I scan my office or school network?

No. ShieldGuard NET only targets the private network this PC is connected to, and there's no way to specify an arbitrary IP address or subnet. We built in this restriction deliberately, since scanning a network without authorization can violate computer-crime laws.

What should I do if a vulnerability is found?

Check your manufacturer's official firmware update information using the vendor/model shown in the results. If the device is end-of-life, replacement is recommended.

Could scanning damage my devices?

Since only read-only port scanning and HTTP banner grabbing are used, normal use will not affect your devices.

Is your home network safe?

A scan takes just minutes and clearly flags any dangerous devices.

Buy ShieldGuard NET ($6.25)