Atlas / MCP servers / martin-ger / ESP32 NAT Router

ESP32 NAT RouterBLOCK

mcp/martin-ger/esp32-nat-router

An AI-enabled NAT Router/Firewall for the ESP32

Verdict
BLOCK
Grade
D
Trust score
65 /100
Exposed tools
38 15r · 17w · 6d
Transport
stdio · streamable-http
License
—
Stars
2,168
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This is a firmware to use the ESP32 as WiFi NAT router. It routes between the network of the AP interface and the STA or ETH interface as uplink network. It can also work as a VPN router using WireGuard as uplink.

Other WiFi Router/Repeater Projects

Starting from this code base I started several spin-off projects with slightly differrent scope. These are all (ab)using the ESP as a minimal network device.

  • Layer 2 WiFi Repeater: Finally we have it - the WiFi Repeater, a layer 2 network bridge between STA and AP (no NAT, no DHCP, just plain frame forwarding in one broadcast domain, i.e. one IP network segment). You currently find it's sources in the esp32_wifi_repeater branch of this repo, that is still under development, but it works generally with good performance and makes it a >2$ WiFi extender.
  • WiFi Access Point: If you have a W32-ET01 board and you are looking for a plain ESP32 Ethernet AP, or correctly for an Ethernet to WiFi Layer 2 Bridge, check out esp32_eth_wifi_bridge.
  • Ethernet Router: If you are looking for an ESP32 NAT router with reverse direction, i.e. WiFi STA as uplink (Internet) and Ethernet as downlink (LAN), check out esp32_ethernet_router. Here I also experiment with support for the common WIZnet W5500 SPI Ethernet NIC.
  • PPPoE Router: If you ever consider using the ESP32 as an open-source ISP router, have a look at the esp32_PPPoE_router. It adds PPPoE as additional Ethernet uplink option. So it could be used directly on an ISP modem.
  • ESP8266 NAT Router/Repeater: The grandfather of all these projects, a feature monster once build on the NONOS-SDK for the ESP8266.

Use cases for the

Read from source at commit 58419bd96996OBSERVED · 2026-09-23
02

Exposed tools (38)

15 read · 17 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
acl_addwriteAdd a firewall ACL rule to the NAT router.
acl_cleardestructiveDelete ALL firewall rules from a list. Traffic will be unrestricted afterwards.
acl_clear_statsdestructiveClear hit count statistics for a firewall ACL list.
acl_deletedestructiveDelete a firewall ACL rule by its index.
add_dhcp_reservationwriteReserve a fixed IP address for a specific device on the hotspot network.
add_portmapwriteForward an incoming port from the internet to a device on the hotspot network.
delete_dhcp_reservationdestructiveRemove a fixed IP reservation for a device. The device will get a dynamic IP next time it connects.
delete_portmapdestructiveRemove a port forwarding rule. The port will no longer be accessible from the internet.
get_ap_statusreadGet the current enabled/disabled state of the WiFi hotspot (AP interface).
get_byte_countsreadShow how many bytes the router has sent and received to/from the internet since last reset.
get_heap_inforeadGet the router
get_ttlreadGet the current TTL (time-to-live) override setting for outgoing internet packets.
get_versionreadGet hardware chip info, firmware version, and build details.
network_tracereadRecord live network traffic from the router and show a human-readable summary.
pcap_get_modereadGet the current packet capture mode (off, acl, or promisc).
pcap_get_snaplenreadGet the maximum number of bytes recorded per captured packet.
pcap_savewriteRecord network traffic from the router and save it to a file.
pcap_set_modewriteSet the packet capture mode. Used to record network traffic for analysis.
pcap_set_snaplenwriteSet the maximum bytes recorded per captured packet.
pcap_statusreadShow packet capture statistics: whether a capture client is connected, and how many packets were captured or dropped.
pingreadPing a host from the router to check connectivity and measure latency. Sends 5 ICMP echo requests.
reset_byte_countsdestructiveReset the internet traffic byte counters to zero.
restartwriteReboot the router. All connected clients will be temporarily disconnected.
set_apwriteSet the name and password of the WiFi hotspot the router broadcasts. Requires restart.
set_ap_enabledwriteEnable or disable the WiFi hotspot (AP interface) immediately, without a reboot.
set_ap_hiddenwriteHide or show the hotspot network name in WiFi scans. Requires restart.
set_ap_ipwriteChange the router
set_ap_macwriteChange the MAC address of the router
set_ap_natwriteEnable or disable NAT on the hotspot (AP) interface. Requires restart.
set_stawriteSet which WiFi network the router connects to for internet access. Requires restart.
set_sta_macwriteChange the MAC address the router uses when connecting to WiFi. Requires restart.
set_sta_staticwriteSet a static IP for the router
set_ttlwriteOverride the TTL (time-to-live) value on all packets sent to the internet. Takes effect immediately.
show_aclreadShow firewall rules and hit counts for upstream (client to internet) and downstream (internet to client) traffic.
show_configreadShow router configuration: the WiFi network it connects to, the hotspot it broadcasts, static IP settings, and web interface state.
show_mappingsreadShow DHCP address pool, reserved IP addresses for specific devices, and port forwarding rules.
show_statusreadShow router status: whether it is connected to WiFi, its IP addresses, how many clients are connected, traffic (shown as B/KB/MB/GB), and free memory.
wifi_scanreadScan for nearby WiFi networks. Returns network name, signal strength, and security type for each.
03

Trust audit

BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
esp_nat_bridge.py:879
"tcpdump is not installed. Install it with: sudo apt install tcpdump"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
esp_nat_bridge.py:1027
"tcpdump is not installed. Install it with: sudo apt install tcpdump"
Why it matters. asks for elevated privileges
MEDIUMInventory / provenance · inv.binary · CWE-1104
firmware_esp32/bootloader.bin
bootloader.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
firmware_esp32/ota_data_initial.bin
ota_data_initial.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
firmware_esp32/partition-table.bin
partition-table.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
firmware_esp32_poe_iso/bootloader.bin
bootloader.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
firmware_esp32_poe_iso/ota_data_initial.bin
ota_data_initial.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
acl_clear, acl_clear_stats, acl_delete, delete_dhcp_reservation, delete_portmap, reset_byte_counts
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:52
2. Open **http://esp32-nat-router.local** (or http://192.168.4.1) in your browser
INFOInventory / provenance · inv.oversize · CWE-1104
ESP32-C3-OLED.png
ESP32-C3-OLED.png
Why it matters. 1385234 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
firmware_esp32/esp32_nat_router.bin
firmware_esp32/esp32_nat_router.bin
Why it matters. 1357824 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
firmware_esp32_poe_iso/esp32_nat_router.bin
firmware_esp32_poe_iso/esp32_nat_router.bin
Why it matters. 1270704 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
firmware_esp32c3/esp32_nat_router.bin
firmware_esp32c3/esp32_nat_router.bin
Why it matters. 1490880 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
firmware_esp32c5/esp32_nat_router.bin
firmware_esp32c5/esp32_nat_router.bin
Why it matters. 1490736 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-09-23 · audit v0.4.1 · source sha 58419bd96996full audit observations/trust-audit/mcp-server/martin-ger__esp32-nat-router.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2358419bd96996BLOCKD65source changed, verdict held
05

Questions

What is the ESP32 NAT Router MCP server?

An AI-enabled NAT Router/Firewall for the ESP32

What tools does ESP32 NAT Router expose?

38 in total: 15 read-only, 17 that write, and 6 that can delete or overwrite (acl_clear, acl_clear_stats, acl_delete, delete_dhcp_reservation, delete_portmap). Every one is listed on this page with its risk.

Is ESP32 NAT Router safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ESP32 NAT Router need?

It reads ESP_NAT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ESP32 NAT Router run?

It speaks stdio and streamable-http, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (58419bd96996), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement