216.73.216.233

T1686.002: Network Device Firewall

View on MITRE ATT&CK The MITRE Corporation · Published 15/04/2026 00:54 · Modified 04/05/2026 16:32

Essential information

MITRE technique ID
T1686.002
Confidence
75/100
Revoked
No
Published
15/04/2026 00:54
Modified
04/05/2026 16:32
Author / Source
The MITRE Corporation

Platforms

Network Devices

Description

Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic. For example, adversaries may add new network firewall rules to allow access to all internal network subnets without restrictions. Allowing access to internal network subsets may enable unrestricted inbound/outbound connectivity or open paths for command and control and lateral movement. Adversaries may obtain access to network device management interfaces via [Valid Accounts](https://attack.mitre.org/techniques/T1078) or by exploiting vulnerabilities. In some cases, threat actors may target firewalls and other network infrastructure that are exposed to the internet by leveraging weaknesses in public-facing applications ([Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).(Citation: CVE-2024-55591 Detail) Adversaries may also modify host networking configurations that indirectly manipulate system firewalls, such as adjusting interface bandwidth or network connection request thresholds.

Kill chain phases

Kill chainPhase
mitre-attack defense-impairment
mitre-attack-v19 defense-impairment

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references