About this tool
Scored checklist for BSNL Bharat Fiber and ADSL modems — admin defaults, Telnet, TR-069 exposure, WPS, UPnP and Wi-Fi encryption.
The BSNL Broadband Router Hardening Checklist scores Bharat Fiber and older ADSL routers for the controls that are most often missed: factory admin accounts, Telnet, WAN-facing web UI, TR-069/CWMP review, WPS, WPA2-AES, UPnP, stale port forwards, guest SSID, DNS and firmware records.
Open BSNL Broadband Router Hardening on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
The copy covers Telnet, TR-069/CWMP and multi-account defaults seen on BSNL-supplied routers.
The score cannot look healthy while critical controls remain open.
Export the score, open critical items and remaining setup time as a plain-text checklist.
Most BSNL Bharat Fiber ONTs and older ADSL modems answer at 192.168.1.1, but the sticker or installation slip should be treated as the final source for your model.
On an ISP-managed ONT, TR-069/CWMP may be needed for provisioning. The checklist asks you to record it and then make sure extra WAN services such as Telnet, FTP, HTTP and UPnP are not open beside it.
Telnet sends credentials without encryption and is a common path for router botnets. If the router offers Telnet, disable it for both LAN and WAN unless you have a controlled maintenance need.
Most BSNL-supplied modems and ONTs use admin/admin for the customer account, with the actual value printed on the label. Many units also carry a second, higher-privilege technician account that is not shown on the sticker, so change the password on every account the user-management page lists and note any you cannot edit so you can raise it with the exchange.