Windows Network Vulnerability Scanning — ShieldGuard NET
Scans routers and devices on your home private network for known vulnerabilities (CVEs) and end-of-life models. A safety-first tool designed so it cannot scan other people's networks.
Safe, read-only scanning.
Known Vulnerability (CVE) Matching
Cross-references detected device vendors and models against a database of known vulnerabilities sourced from the CISA Known Exploited Vulnerabilities (KEV) catalog. See our explainer article for how CVEs and the KEV catalog work.
TCP Port Scanning
Connect scans only. No SYN scans or raw sockets are used.
HTTP Banner Grabbing
Vendor and model are inferred using read-only GET requests only.
End-of-Life Detection
Flags devices whose manufacturer support has ended and suggests replacement.
What it doesn't do (by design)
- Never attempts to exploit vulnerabilities
- Never attempts credential guessing or brute-forcing
- Cannot scan networks other than your own (a deliberate restriction)
- Does not retrieve exact firmware versions — since detection relies on inferring the model from an HTTP banner rather than SNMP or vendor-specific APIs, model and vulnerability matches are for reference only
Specifications
| Supported OS | Windows 10 / 11 (64-bit) |
|---|---|
| Scan scope | Only the private network this PC is connected to (RFC 1918) |
| Vulnerability data | CISA KEV catalog, NVD public data |
| Implementation | Rust |
| Price | $6.25 (one-time, no subscription) |
| License | One license per PC |
| Base engine | Redesigned for Windows and consumer use from the open-source router-cve-audit (MIT) |
Learn more
How to Check Your Home Network for Vulnerabilities
What CVEs and the KEV catalog are, and why home routers get targeted.
A Windows 10/11 Security Checklist
Thinking beyond your PC to your whole home network.
What Is Windows Antivirus Software?
How antivirus, EDR, and network scanning roles differ.
Frequently asked questions
Can I scan my office or school network?
No. ShieldGuard NET only targets the private network this PC is connected to, and there's no way to specify an arbitrary IP address or subnet. We built in this restriction deliberately, since scanning a network without authorization can violate computer-crime laws.
What should I do if a vulnerability is found?
Check your manufacturer's official firmware update information using the vendor/model shown in the results. If the device is end-of-life, replacement is recommended.
Could scanning damage my devices?
Since only read-only port scanning and HTTP banner grabbing are used, normal use will not affect your devices.
Is your home network safe?
A scan takes just minutes and clearly flags any dangerous devices.
Buy ShieldGuard NET ($6.25)