Network port detail · UDP/TCP

2082

Infowave
Protocol(s)
UDP/TCP
Range
Registered (1024-49151)

Summary

// if you see it open
cPanel login served over cleartext HTTP on 2082 — usernames, passwords, and session cookies are transmitted unencrypted and exposed to interception (MITM). The port is heavily scanned for credential-stuffing and brute-force attacks; cPanel ships cPHulk Brute Force Protection to throttle them. In scope of CVE-2026-41940 (CVSS 9.8): a CRLF-injection auth bypass in cPanel & WHM session-file parsing let an unauthenticated remote attacker forge a root session (user=root/hasroot=1/tfa_verified=1) with no password or 2FA; zero-day exploitation observed as early as Feb 2026, patched April 2026. Guidance: disable 2082 and force HTTPS on 2083; never expose the panel directly to the internet.
// analyst note
Treat an open 2082 as a cPanel control panel served in the clear — recommend disabling it in favor of 2083 (HTTPS). The IANA infowave name is essentially a paper assignment with no real-world traffic.
[ 01 ] — Context

About port 2082/tcp.

Updated  ·  Confidence: High  ·  7 sources  ·  How this page is checked

Port 2082/tcp carries a split identity that an analyst should hold in mind at once. IANA registers it as infowave with the description "Infowave Mobility Server," assignee and contact Kaz Kylheku, and a blank reference field — dual-registered on TCP and UDP, with no registration or modification date recorded in the registry and no RFC cited. Infowave's Mobility Server was middleware for managing mobile-device access to enterprise resources over wireless links; it has essentially no modern footprint and is not in active commercial use. The reason port 2082 shows up in real traffic is almost entirely cPanel: it is cPanel's default *unencrypted* HTTP port for the end-user control panel, reached as http://domain.com:2082/. The TLS equivalent is 2083, and the WHM (WebHost Manager) pair is 2086 (HTTP) / 2087 (HTTPS). Because the cPanel listener serves a login form in cleartext, port 2082 is a recurring security liability: credentials and session cookies travel unencrypted and are exposed to interception, and the port is heavily scanned for credential-stuffing and brute-force attacks (cPanel ships cPHulk to throttle these). The exposure is large — Shodan-derived counts cited in vendor reporting put roughly 1.5 million internet-facing cPanel/WHM instances across 2082/2083/2086/2087. It is also in the blast radius of CVE-2026-41940 (CVSS 9.8), a CRLF-injection authentication bypass in cPanel & WHM session-file parsing that let an unauthenticated remote attacker forge a root session (no password or 2FA), with zero-day exploitation observed weeks before the April 2026 patch. Current guidance is uniform: disable 2082 and force HTTPS on 2083, and never expose the panel directly to the internet.

IANA assignment
infowave — "Infowave Mobility Server"; reference (blank — no RFC in IANA registry); assignee/contact Kaz Kylheku; dual-registered 2082/tcp + 2082/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (lines 3926/3927; iana.org)
Registration/modification date
blank in registry — none recorded (not fabricated) [Confirmed] — IANA registry
Range class
registered (1024–49151)
Prevalence/exposure
~1.5M internet-exposed cPanel/WHM instances across 2082/2083/2086/2087 (Shodan, April 2026, via vendor reporting) [Likely] — Picus Security blog (secondary Shodan citation)
Related ports
2083 (cPanel HTTPS), 2086 (WHM HTTP), 2087 (WHM HTTPS); contrast 2095/2096 (webmail)

Security implications

cleartext HTTP login (credential/cookie interception, MITM); high-volume brute-force/credential-stuffing target (cPHulk mitigates); in scope of CVE-2026-41940 (CVSS 9.8) cPanel/WHM CRLF session-injection auth bypass → forged root session, zero-day exploited ~Feb 2026, patched April 2026

[Confirmed/Threat-reported] — NVD CVE-2026-41940, Rapid7, Picus, Help Net Security

Typically seen on

shared/managed web-hosting servers running cPanel (HostGator, Bluehost, etc.); rarely anything Infowave-related

Primary (de-facto) use
cPanel default unencrypted HTTP control-panel port, http://domain.com:2082/; encrypted equivalent is 2083, WHM is 2086/2087 [Confirmed] — ESDS cPanel port KB, tecadmin.net, whatportis.com
Software
cPanel & WHM (dominant); Infowave Mobility Server (IANA-registered, legacy/obscure) [Confirmed] — accesschecker.net, whatportis.com
Analyst note
Treat an open 2082 as a cPanel control panel served in the clear — recommend disabling it in favor of 2083 (HTTPS). The IANA infowave name is essentially a paper assignment with no real-world traffic.
[ 02 ] — Context

About port 2082/udp.

Updated  ·  Confidence: High  ·  5 sources  ·  How this page is checked

Port 2082/udp is registered with IANA as infowave with the description "Infowave Mobility Server," assignee Kaz Kylheku, and blank registration-date and reference fields — a true dual registration shared with 2082/tcp, which carries identical service-name and description data. Infowave Mobility Server was an enterprise mobility middleware platform that let wireless and mobile devices synchronize with and reach back-end corporate resources, providing protocol translation, session management, and data compression suited to bandwidth-constrained wireless links; the product is not meaningfully present on the modern internet. For an analyst, the practically important fact about port 2082 is that almost all real-world traffic and tooling interest centers on the TCP variant, not UDP: 2082/tcp is the de-facto unencrypted (HTTP) cPanel/WHM web hosting control-panel port found on shared-hosting servers, and hosting-provider firewall guidance routinely recommends restricting 2082/tcp to trusted addresses and preferring 2083/tcp (HTTPS). That cPanel association is an unofficial, de-facto use that applies to TCP only — there is no documented cPanel role for 2082/udp, and the IANA registration itself is the Infowave product, not cPanel. No security literature specific to the UDP Infowave service was found; port-scanning databases (Nmap, Shodan) track 2082 chiefly because of cPanel/TCP prevalence. For UDP specifically, a responsive 2082/udp is uncommon and, given the defunct Infowave product, worth treating as an anomaly to investigate rather than an expected service.

IANA assignment
infowave — "Infowave Mobility Server"; reference (blank — no RFC cited in IANA registry); assignee Kaz Kylheku; dual-registered 2082/tcp + 2082/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (line 3927)
Range class
registered (1024–49151)
Registration date
blank in IANA registry (genuine blank, not fabricated) [Confirmed] — IANA registry line 3927
IANA reference
blank in IANA registry [Confirmed] — IANA registry line 3927
Related ports
2083 (cPanel HTTPS), 2086/2087 (WHM HTTP/HTTPS), 2095/2096 (webmail) — the cPanel control-panel cluster, all TCP de-facto

Primary use

Infowave Mobility Server — enterprise mobile middleware for device-to-backend sync, protocol translation, session management, and data compression over wireless links; largely defunct

[Confirmed] — IANA registry; https://whatportis.com/ports/2082_infowave-mobility-server

Other/unofficial uses

cPanel/WHM unencrypted (HTTP) web hosting control panel — de-facto, TCP only; no documented cPanel role for 2082/udp

[Likely] — https://tecadmin.net/ports-to-open-for-whm-cpanel/ ; https://accesschecker.net/en/tools/port-lookup/2082

Security implications

cPanel exposure (firewall guidance: restrict 2082/tcp to trusted IPs, prefer 2083/tcp HTTPS) applies to TCP; no documented attack surface unique to 2082/udp; scanning interest (Nmap/Shodan) is driven by cPanel/TCP prevalence, not UDP

[Likely] — https://tecadmin.net/ports-to-open-for-whm-cpanel/ ; https://data-status.shodan.io/ports.html

Typically seen on

legacy/defunct Infowave Mobility deployments (UDP); a responsive 2082/udp today is uncommon and worth investigating

Analyst note
Distinguish transport — the cPanel reputation belongs to 2082/tcp; the IANA registration (both transports) is the Infowave product. UDP-specific traffic is rare and not cPanel.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
infowave UDP Infowave Mobiltiy Server 0.03%
infowave TCP Infowave Mobility Server 0.01%
IANA name
infowave
Transport
TCP
Range
Registered (1024-49151)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.