HomeSecurityOver 30 Netgear routers vulnerable

More than 30 Netgear routers vulnerable

Are you using a Netgear router? Researchers discovered a very serious security flaw affecting hundreds of thousands of Netgear devices.

Security company Trustwave reports that the vulnerability essentially allows attackers to exploit the router password recovery system to bypass authentication and, using administrator credentials, they manage to gain full access to the device and its settings.Netgear

What is particularly concerning is that the security flaw is found in at least 31 different Netgear models, leaving over a million users exposed to attacks.

The most concerning thing is the fact that these devices could, in some cases, be breached remotely. As explained by Trustwave researcher Simon Kenin, any router that has remote management enabled is vulnerable to hack.

We should note that the remote management capability is disabled by default on most devices, and the company reports that it has found over 10 thousand routers that have been compromised, but the actual number could be “over one million.”

Kenin also warns that anyone with physical access to a faulty Netgear router can exploit its defensive mechanisms and gain access to the device, adding the router to botnets.

“The vulnerability can be exploited by a remote intruder if remote management is enabled. By default the feature is not enabled. However, anyone with physical access to a network with a vulnerable router can exploit it at a local level” said the researcher.

“This also includes public Wi-Fi spaces, such as cafés and libraries that use vulnerable equipment.”

Trustwave reported the vulnerability to the National Vulnerability Database. Netgear also confirmed the flaw in a post on its website, giving the full list of affected models:

  • R8500
  • R8300
  • R7000
  • R6400
  • R7300DST
  • R7100LG
  • R6300v2
  • WNDR3400v3
  • WNR3500Lv2
  • R6250
  • R6700
  • R6900
  • R8000
  • R7900
  • WNDR4500v2
  • R6200v2
  • WNDR3400v2
  • D6220
  • D6400
  • C6300 (firmware released to ISPs)
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS