-
Notifications
You must be signed in to change notification settings - Fork 0
WebGUI Remote Access
TAILCAT ZER0 lets you access your Asuswrt-Merlin router's graphical administration interface (WebGUI) from anywhere in the worldβeven from behind a strict CGNAT, mobile hotspot, or double-NATβwithout opening a single WAN port on your router.
Historically, managing an Asuswrt router remotely required enabling "Web Access from WAN" in Administration β System. This exposes the router's web server (httpd) directly to port scanners, brute-force bots, and zero-day vulnerabilities across the public internet.
Traditional VPN setups (OpenVPN or standard WireGuard) require:
- A public, routable WAN IPv4 address.
- Dynamic DNS (DDNS) setup.
- Opening UDP ports on your WAN firewall.
- Exporting, distributing, and importing
.ovpnor.conffiles onto client devices.
TAILCAT ZER0 creates an ephemeral encrypted WireGuard tunnel targeting your router's internal loopback interface (127.0.0.1:8443 or 127.0.0.1:80).
[Remote Laptop] [Asuswrt Router]
+-------------------+ +-------------------+
| Web Browser | | |
| https:// | | |
| localhost:8443 | | |
+---------+---------+ | |
| | |
v | |
+-------------------+ P2P WireGuard Tunnel +-------------------+
| tailcat forward | ==============================> | TailCat Engine |
| <TOKEN> 8443 | (Encrypted via DERP) | (Local) |
+-------------------+ +---------+---------+
|
v
+-------------------+
| Asuswrt WebGUI |
| 127.0.0.1:8443 |
+-------------------+
- No WAN ports opened: Completely invisible to internet port scanners (Shodan, Censys).
- CGNAT / 4G / 5G Friendly: Works behind Starlink, mobile hotspots, and CGNAT ISPs.
- Ephemeral: Automatically tears down when your session timer expires.
- Run
tailcatzero. - Select Option 4 (π Expose Router WebGUI).
- TAILCAT ZER0 automatically inspects NVRAM (
https_lanport/http_lanport), binds the tunnel, and renders the dedicated WebGUI Active Session Card:
TAILCAT ZER0 v1.7.1 β±|γ
(ΛΛ γ7
|γΛγ΅
Instant Tunnel Manager γγΛ,)γ
========================================================================
π± TAILCAT ZER0 β Active Session
========================================================================
Service: π Router WebGUI (Port 8443)
Destination: https://192.168.50.1:8443 (Ports: 8443,80)
Auto-Kill: β±οΈ 30m remaining
Security: π WireGuard P2P Encrypted (Zero WAN Ports Open)
π¬ Copy & Paste to Friend / Admin Support:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Hey, I've opened a temporary TailCat session on my router (30m remaining).
1. Run: tailcat forward tcpGFwWCBVZX0... 8443
2. Open browser: https://localhost:8443
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
========================================================================
π Stop | π± QR Code | π Refresh | β©οΈ Back:
tailcatzero webguiOn your remote laptop or workstation (macOS, Linux, or Windows with tailcat installed):
βββ(admin@laptop)-[~]
ββ$ tailcat forward tcpGFwWCBVZX0y0H46ZJ_qK... 8443
[+] Connecting to WireGuard peer via DERP relay (fra)...
[+] Direct WireGuard connection established (UDP 192.168.50.1:51820)
[+] Local listener bound: 127.0.0.1:8443
[+] Forwarding TCP traffic -> router loopback 127.0.0.1:8443
[β] Tunnel active! Open your browser to: https://localhost:8443
(Press Ctrl+C to terminate session)
Open your favorite browser and visit:
https://localhost:8443
- Bypass Certificate Warning: Since Asuswrt uses a self-signed SSL certificate, your browser will display an "Untrusted Connection" or "Your connection is not private" notice. Click Advanced β Proceed to localhost (unsafe).
- Log In: Log into the Asuswrt-Merlin interface with your regular admin credentials.
- You now have full, fast, responsive access to the router dashboard, wireless settings, VPN director, AiMesh nodes, and system logs!
When you finish managing the router:
- Press
Ctrl+Con your laptop in thetailcat forwardterminal. - Stop the tunnel on the router:
- Via TUI: Press
vβ Presss. - Via CLI:
tailcatzero stop WEBGUI
- Via TUI: Press
TAILCAT ZER0 β’ Ephemeral WireGuard Management for Asuswrt-Merlin β’ GitHub Repository