HomeSecurityNetgear has not patched six vulnerabilities in the Nighthawk router

Netgear has not patched six vulnerabilities in its Nighthawk router

Researchers have found six high-risk vulnerabilities in the latest firmware version for the Netgear Nighthawk R6700v3 router. At the time of publication, the flaws remain unpatched.

Netgear

See also: Netgear: $1,500 Wi-Fi 6E Mesh router will make your home smart

The Nighthawk R6700 is a popular dual-band WiFi router that is touted with gaming-focused features, smart parental controls, and internal hardware that is powerful enough to meet the needs of home power users.

The six flaws were discovered by researchers at cybersecurity firm Tenable and could allow an attacker on the network to take complete control of the device:

  • CVE-2021-20173: A post-authentication command injection flaw in the device's update functionality, making it susceptible to command injection.
  • CVE-2021-20174: HTTP is used by default in all device web interface communications, with the risk of username and password interception in clear text.
  • CVE-2021-20175: The SOAP interface (port 5000) uses HTTP for communication by default, risking username and password interception in clear text.
  • CVE-2021-23147: Unauthenticated root execution via UART port connection. Exploiting this flaw requires physical access to the device.
  • CVE-2021-45732: Configuration manipulation via hardcoded encryption routines, allowing changes to settings that are locked for security reasons.
  • CVE-2021-45077: All usernames and passwords for device services are stored in plain text in the configuration file.

In addition to the aforementioned security issues, Tenable found several instances of jQuery libraries based on version 1.4.2, which is known to contain vulnerabilities. The researchers also note that the device uses a MiniDLNA server version with publicly known flaws.

See also: Netgear: Fixes dangerous code execution flaw in many routers

The newly revealed flaws affect firmware version 1.0.4.120, which is the latest version for the device.

Users are advised to change default credentials to something unique and strong and follow recommended security practices for stronger defense against malware infections.

Netgear

Also, check firmware download portal and install new versions as they become available. It is also recommended to enable automatic updates on your router.

The current security advisory refers to the Netgear R6700 v3, which is still supported, not the Netgear R6700 v1 and R6700 v2, which have expired. If you are still using the older models, it is recommended that you upgrade them.

See also: Netgear: Fixes serious bugs in over a dozen smart switches

Tenable disclosed the above issues to the vendor on September 30, 2021, and although some information exchange in the form of clarifications and suggestions took place thereafter, the problems remain unresolved.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS