ESP32 NAT RouterBLOCK
An AI-enabled NAT Router/Firewall for the ESP32
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This is a firmware to use the ESP32 as WiFi NAT router. It routes between the network of the AP interface and the STA or ETH interface as uplink network. It can also work as a VPN router using WireGuard as uplink.
Other WiFi Router/Repeater Projects
Starting from this code base I started several spin-off projects with slightly differrent scope. These are all (ab)using the ESP as a minimal network device.
- Layer 2 WiFi Repeater: Finally we have it - the WiFi Repeater, a layer 2 network bridge between STA and AP (no NAT, no DHCP, just plain frame forwarding in one broadcast domain, i.e. one IP network segment). You currently find it's sources in the esp32_wifi_repeater branch of this repo, that is still under development, but it works generally with good performance and makes it a >2$ WiFi extender.
- WiFi Access Point: If you have a W32-ET01 board and you are looking for a plain ESP32 Ethernet AP, or correctly for an Ethernet to WiFi Layer 2 Bridge, check out esp32_eth_wifi_bridge.
- Ethernet Router: If you are looking for an ESP32 NAT router with reverse direction, i.e. WiFi STA as uplink (Internet) and Ethernet as downlink (LAN), check out esp32_ethernet_router. Here I also experiment with support for the common WIZnet W5500 SPI Ethernet NIC.
- PPPoE Router: If you ever consider using the ESP32 as an open-source ISP router, have a look at the esp32_PPPoE_router. It adds PPPoE as additional Ethernet uplink option. So it could be used directly on an ISP modem.
- ESP8266 NAT Router/Repeater: The grandfather of all these projects, a feature monster once build on the NONOS-SDK for the ESP8266.
Use cases for the
58419bd96996OBSERVED · 2026-09-23Exposed tools (38)
15 read · 17 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
acl_add | write | Add a firewall ACL rule to the NAT router. |
acl_clear | destructive | Delete ALL firewall rules from a list. Traffic will be unrestricted afterwards. |
acl_clear_stats | destructive | Clear hit count statistics for a firewall ACL list. |
acl_delete | destructive | Delete a firewall ACL rule by its index. |
add_dhcp_reservation | write | Reserve a fixed IP address for a specific device on the hotspot network. |
add_portmap | write | Forward an incoming port from the internet to a device on the hotspot network. |
delete_dhcp_reservation | destructive | Remove a fixed IP reservation for a device. The device will get a dynamic IP next time it connects. |
delete_portmap | destructive | Remove a port forwarding rule. The port will no longer be accessible from the internet. |
get_ap_status | read | Get the current enabled/disabled state of the WiFi hotspot (AP interface). |
get_byte_counts | read | Show how many bytes the router has sent and received to/from the internet since last reset. |
get_heap_info | read | Get the router |
get_ttl | read | Get the current TTL (time-to-live) override setting for outgoing internet packets. |
get_version | read | Get hardware chip info, firmware version, and build details. |
network_trace | read | Record live network traffic from the router and show a human-readable summary. |
pcap_get_mode | read | Get the current packet capture mode (off, acl, or promisc). |
pcap_get_snaplen | read | Get the maximum number of bytes recorded per captured packet. |
pcap_save | write | Record network traffic from the router and save it to a file. |
pcap_set_mode | write | Set the packet capture mode. Used to record network traffic for analysis. |
pcap_set_snaplen | write | Set the maximum bytes recorded per captured packet. |
pcap_status | read | Show packet capture statistics: whether a capture client is connected, and how many packets were captured or dropped. |
ping | read | Ping a host from the router to check connectivity and measure latency. Sends 5 ICMP echo requests. |
reset_byte_counts | destructive | Reset the internet traffic byte counters to zero. |
restart | write | Reboot the router. All connected clients will be temporarily disconnected. |
set_ap | write | Set the name and password of the WiFi hotspot the router broadcasts. Requires restart. |
set_ap_enabled | write | Enable or disable the WiFi hotspot (AP interface) immediately, without a reboot. |
set_ap_hidden | write | Hide or show the hotspot network name in WiFi scans. Requires restart. |
set_ap_ip | write | Change the router |
set_ap_mac | write | Change the MAC address of the router |
set_ap_nat | write | Enable or disable NAT on the hotspot (AP) interface. Requires restart. |
set_sta | write | Set which WiFi network the router connects to for internet access. Requires restart. |
set_sta_mac | write | Change the MAC address the router uses when connecting to WiFi. Requires restart. |
set_sta_static | write | Set a static IP for the router |
set_ttl | write | Override the TTL (time-to-live) value on all packets sent to the internet. Takes effect immediately. |
show_acl | read | Show firewall rules and hit counts for upstream (client to internet) and downstream (internet to client) traffic. |
show_config | read | Show router configuration: the WiFi network it connects to, the hotspot it broadcasts, static IP settings, and web interface state. |
show_mappings | read | Show DHCP address pool, reserved IP addresses for specific devices, and port forwarding rules. |
show_status | read | Show router status: whether it is connected to WiFi, its IP addresses, how many clients are connected, traffic (shown as B/KB/MB/GB), and free memory. |
wifi_scan | read | Scan for nearby WiFi networks. Returns network name, signal strength, and security type for each. |
Trust audit
BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (16)
"tcpdump is not installed. Install it with: sudo apt install tcpdump"
"tcpdump is not installed. Install it with: sudo apt install tcpdump"
bootloader.bin
ota_data_initial.bin
partition-table.bin
bootloader.bin
ota_data_initial.bin
system use found in code, not declared in the description
acl_clear, acl_clear_stats, acl_delete, delete_dhcp_reservation, delete_portmap, reset_byte_counts
2. Open **http://esp32-nat-router.local** (or http://192.168.4.1) in your browser
ESP32-C3-OLED.png
firmware_esp32/esp32_nat_router.bin
firmware_esp32_poe_iso/esp32_nat_router.bin
firmware_esp32c3/esp32_nat_router.bin
firmware_esp32c5/esp32_nat_router.bin
Gates applied: no_behavioural_pass, no_license.
58419bd96996full audit observations/trust-audit/mcp-server/martin-ger__esp32-nat-router.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 58419bd96996 | BLOCK | D | 65 | source changed, verdict held |
Questions
What is the ESP32 NAT Router MCP server?
An AI-enabled NAT Router/Firewall for the ESP32
What tools does ESP32 NAT Router expose?
38 in total: 15 read-only, 17 that write, and 6 that can delete or overwrite (acl_clear, acl_clear_stats, acl_delete, delete_dhcp_reservation, delete_portmap). Every one is listed on this page with its risk.
Is ESP32 NAT Router safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ESP32 NAT Router need?
It reads ESP_NAT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ESP32 NAT Router run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (58419bd96996), read on 2026-09-23. The repository is watched and re-audited when it changes.