Story image

Full list of NETGEAR router vulnerabilities revealed - is your device on the list?

09 Feb 2018

Many NETGEAR routers were subject to vulnerabilities that allowed attackers to take control of the devices through a password recovery feature.

Trustwave Spiderlabs researcher Martin Rakhmanov discovered the vulnerabilities last year. After a period of responsible disclosure and patching, he has revealed the five vulnerabilities:

1: Password recovery and file access on some routers and modem routers (PSV-2017-0677)

This vulnerability allows an attacker to read any file on the device as well as accessing administrative credentials by manipulating a password recovery feature.

This vulnerability affects 17 different Netgear products.

  • D8500 running firmware versions 1.0.3.27 and earlier
  • DGN2200v4 running firmware versions 1.0.0.82 and earlier
  • R6300v2 running firmware versions 1.0.4.06 and earlier
  • R6400 running firmware versions 1.0.1.20 and earlier
  • R6400v2 running firmware versions 1.0.2.18 and earlier
  • R6700 running firmware versions 1.0.1.22 and earlier
  • R6900 running firmware versions 1.0.1.20 and earlier
  • R7000 running firmware versions 1.0.7.10 and earlier
  • R7000P running firmware versions 1.0.0.58 and earlier
  • R7100LG running firmware versions 1.0.0.28 and earlier
  • R7300DST running firmware versions 1.0.0.52 and earlier
  • R7900 running firmware versions 1.0.1.12 and earlier
  • R8000 running firmware versions 1.0.3.46 and earlier
  • R8300 running firmware versions 1.0.2.86 and earlier
  • R8500 running firmware versions 1.0.2.86 and earlier
  • WNDR3400v3 running firmware versions 1.0.1.8 and earlier
  • WNDR4500v2 running firmware versions 1.0.0.62 and earlier

2: Post-authentication command injection on some router and modem routers (PSV-2017-1207)

Allows any logged in user to execute any existing command on the appliance as root.

This vulnerability affects six different Netgear products.

  • D8500 running firmware versions 1.0.3.28 and earlier
  • R6400 running firmware versions 1.0.1.22 and earlier
  • R6400v2 running firmware versions 1.0.2.18 and earlier
  • R8300 running firmware versions 1.0.2.94 and earlier
  • R8500 running firmware versions 1.0.2.94 and earlier
  • R6100 running firmware versions 1.0.1.12 and earlier

3: Authentication bypass on some router and modem routers (PSV-2017-1208)

Allows any attacker to bypass the need to authenticate. This vulnerability affects 17 different Netgear products.

  • D6220, running firmware versions prior to 1.0.0.26
  • D6400, running firmware versions prior to 1.0.0.60
  • D8500, running firmware versions prior to 1.0.3.29
  • R6250, running firmware versions prior to 1.0.4.12
  • R6400, running firmware versions prior to 1.01.24
  • R6400v2, running firmware versions prior to 1.0.2.30
  • R6700, running firmware versions prior to 1.0.1.22
  • R6900, running firmware versions prior to 1.0.1.22
  • R6900P, running firmware versions prior to 1.0.0.56
  • R7000, running firmware versions prior to 1.0.9.4
  • R7000P, running firmware versions prior to 1.0.0.56
  • R7100LG, running firmware versions prior to 1.0.0.32
  • R7300DST, running firmware versions prior to 1.0.0.54
  • R7900, running firmware versions prior to 1.0.1.18
  • R8000, running firmware versions prior to 1.0.3.44
  • R8300, running firmware versions prior to 1.0.2.100_1.0.82
  • R8500, running firmware versions prior to 1.0.2.100_1.0.82

4: Chained attack for command injection on some routers and modem routers (PSV-2017-1209)

By combining these vulnerabilities together any user connected to the router can run OS commands as root on the device without providing any credentials.

This vulnerability affects 17 different Netgear products.

  • D6220, running firmware versions prior to 1.0.0.26
  • D6400, running firmware versions prior to 1.0.0.60
  • D8500, running firmware versions prior to 1.0.3.29
  • R6250, running firmware versions prior to 1.0.4.12
  • R6400, running firmware versions prior to 1.01.24
  • R6400v2, running firmware versions prior to 1.0.2.30
  • R6700, running firmware versions prior to 1.0.1.22
  • R6900, running firmware versions prior to 1.0.1.22
  • R6900P, running firmware versions prior to 1.0.0.56
  • R7000, running firmware versions prior to 1.0.9.4
  • R7000P, running firmware versions prior to 1.0.0.56
  • R7100LG, running firmware versions prior to 1.0.0.32
  • R7300DST, running firmware versions prior to 1.0.0.54
  • R7900, running firmware versions prior to 1.0.1.18
  • R8000, running firmware versions prior to 1.0.3.44
  • R8300, running firmware versions prior to 1.0.2.100_1.0.82
  • R8500, running firmware versions prior to 1.0.2.100_1.0.82

5: Command injection vulnerability on D7000, EX6200v2, and some routers (PSV-2017-2181)

Setting a specific "device_name" parameter allows any user to execute any command if they use WPS to join the network.

This vulnerability affects six different Netgear products.

  • R6100 running firmware versions prior to 1.0.1.14
  • R7500 running firmware versions prior to 1.0.0.110
  • R7500v2 running firmware versions prior to 1.0.3.16
  • R7800 running firmware versions prior to 1.0.2.32
  • EX6200v2 running firmware versions prior to 1.0.1.50
  • D7800 running firmware versions prior to 1.0.1.22

Netgear and Trustwave both urge all device owners to update their firmware by visiting Netgear support, entering their router's model number, downloading and installing the latest firmware for their device.

IoT and DDoS attacks: A match made in heaven
A10 Network’s Adrian Taylor uses findings from a number of reports to illustrate his point that advances in technology are facilitating cybercrime.
ForgeRock launches Sandbox-as-a-Service to facilitate compliance
The cloud-based testing environment for APIs enables banks to accelerate compliance with Open Banking and PSD2 deadlines.
Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
Flashpoint: APAC companies must factor geopolitics in cyber strategies
The diverse geopolitical and economic interests of the states in the region play a significant role in driving and shaping cyber threat activity against entities operating in APAC.
Expert offers password tips to aid a stress-free sleep
For many cybersecurity professionals, the worries of the day often crawl into night-time routines - LogMeIn says better password practices can help.