Eagle Eye Networks

Netgear Router Vulnerability

December 13, 2016 Eagle Eye Networks

NetGear-transparent

Netgear R7000 and R6400 routers, and maybe other ones too (see list below) were discovered to have a severe vulnerability on Dec 9, 2016.

Netgear responded within 3 days with a new firmware to solve the problem. Good work on their part.

But if you don’t patch and upgrade it is really quite easy to lose to control of your router and grant bad actors total access to your network and router. You will then be subject to a whole list of issues that may be really difficult to clean up.

Here is the CERN posting that details the vulnerability:
https://www.kb.cert.org/vuls/id/582384

Here is an article with additional details:
https://securityledger.com/2016/12/vulnerability-prompts-warning-stop-using-netgear-wifi-routers/

Calypso Pink indicates all of these Netgear routers are vulnerable:
https://kalypto.org/research/netgear-vulnerability-expanded/

NetGear AC1750-Smart WiFi Router (Model R6400) NetGear AC1900-Nighthawk Smart WiFi Router (Model R7000) NetGear AC2300-Nighthawk Smart WiFi Router with MU-MIMO (Model R7000P) NetGear AC2350-Nighthawk X4 AC 2350 Dual Band WiFi Router (Model R7500) NetGear AC2600-Nighthawk X4S Smart WiFi Gaming Router (Model R7800) NetGear AC3200-Nighthawk AC3200 Tri-Band WiFi Router (Model R8000) NetGear AC5300-AC5300 Nighthawk X8 Tri-Band WiFi Router (Model R8500) NetGear AD7200-Nighthawk X10 Smart WiFi Router (R9000)

netgear1450x1214

Other posts that might interest you

loading

145,000 DVRs Compromised

Several articles, including one by the Wall Street Journal, have recently reported that approximately 145,000 hacked DVRs and cameras were used to create some of the largest denial of service…

September 30, 2016 Eagle Eye Networks

Are You Afraid of Your DVR?

You should be if it's connected to the internet. It could be the doorway for hackers to access your entire network. Once a DVR is compromised, it can be used…

October 31, 2016 Eagle Eye Networks

DDOS Cyber Attacks Update

Last week hackers forced Brian Krebs to take down his security journalism site because of a large scale Denial of Service Attack - likely one of the largest ever seen.…

September 29, 2016 Eagle Eye Networks