Living on a prayer? Netgear not quite halfway there with patches for 28 out of 79 vulnerable router models
- Reference: 1593541684
- News link: https://www.theregister.co.uk/2020/06/30/netgear_router_patches_28_of_79_done/
- Source link:
The latest hotfixes come after two models were fixed earlier in June. The vulnerability in question could, for example, allow the opening of a superuser-level telnet backdoor, [1]as we reported at the time .
Over the past few weeks Netgear has been pushing out fixes, having so far plugged problems with 28 of the 79 models it says are affected by the unwanted remote-superuser flaw.
The vulnerabilities, initially discovered by Trend Micro's Zero Day Initiative (ZDI) in January, were meant to have been patched by 15 June. Netgear asked for an extension at the end of May for a further month, prompting the ZDI to publish an advisory note.
An infosec outfit called Grimm followed that up by releasing [2]live exploit code for two of the unfixed vulns, which stung Netgear into patching two devices early on.
"Multiple Netgear devices contain a stack buffer overflow in the httpd web server's handling of upgrade_check.cgi, which may allow for unauthenticated remote code execution with root privileges," said America's Carnegie-Mellon University in a note from its Software Engineering Institute [3]summarising the problem.
Basically, an attacker could bypass authentication and do whatever they pleased with your router, such as installing malware to sniff out login creds. As ZDI's Abdul-Aziz Hariri told us earlier this month: "In most scenarios, the attacker would be able to possibly upload a custom backdoor software and establish persistence or launch further attacks, like man-in-the-middle attacks."
The latest batch of hotfixes are [4]available on Netgear's website , along with a health warning that full regression testing hasn't been carried out on all the affected devices.
Translation: it shouldn't cause problems, but your mileage may vary. This latest wording seems to omit the word "beta" that was in the first version of the Netgear advisory as reported by El Reg on 19 June, potentially suggesting greater confidence in the stability of the hotfixes.
"Netgear plans to release firmware updates that fix these vulnerabilities for all affected products that are within the security support period," the company said on its knowledge base page. Whether your device is or is not supported, the firm suggests double-checking affected router models to ensure the built-in remote management gateway is disabled.
"The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to update to the most recent firmware version and to replace end-of-life devices that are no longer supported with security patches," said the US computer security agency in a note issued last night.
We have asked Netgear for detailed comment on the length of time it seems to be taking to issue hotfixes for all affected routers. ®
Get our [5]Tech Resources
[1] https://www.theregister.com/2020/06/19/netgear_bug_disclosure/
[2] https://blog.grimm-co.com/2020/06/soho-device-exploitation.html
[3] https://www.kb.cert.org/vuls/id/576779
[4] https://kb.netgear.com/000061982/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders
[5] https://whitepapers.theregister.com/
Re: Who give's the bad guys access to their router's web server?
It's usually JavaScript in a compromised/malware web page that tries to connect to 192.168.1.1 and other likely suspects.
Wonder how many router firmware developers Netgear has?
I'm guessing one highly competent developer/lead and maybe one or two others who work under the lead. And how many different processors/chipsets are affected by this error? This may put a real crimp in Netgear's new router development.
The race to the bottom isn't just in price!
Re: Wonder how many router firmware developers Netgear has?
My impression from getting support on Netgear products is that engineering is outsourced. There were entire classes of features that didn't work, public releases sometimes had testing backdoors permanently enabled, and support needed multiple days to contact engineering. The only satisfactory solution I came up with was throwing them in the trash.
Don't forget Layer 2...
This isn't really anything to do with vulnerabilities, just a comment on Netgear's L2 switch issues.
Because I'm personally on a budget (Solved due to the donation of plenty of Cisco kit - thanks, Richard!), and work is definitely on a budget, I've been forced into useing Netgear switches (GS105/108/GS308E) at home and GS10x/GS724/FS728 at the SMB where I currently labour.
I have all sorts of 'beefs' with these blasted things..
* The GS105/108s lock up when subjected to (undiagnosed packets from) WinPE and the GS724/FS728 have individual ports that 'lock up' intermittently, so much so that one has a large-ish script ('Smart Managed' is not 'Properly Managed', you know) that spots locked up ports and down/ups them. MD/CEO is deaf to the "it's your bloody surface pro doing that" argument I present....
* The GS308E isn't manageable with a particular device attached... looks like the CPU is maxed out trying to make sense of something.
The other thing that pisses me off is that rather than change the model number like most people, they just change the *version* number ('Model X, Version Y'). I deliberately asked for a very specific thing to match some existing infrastructure (Version 4), and 'coz purchasing is done by Boss I got the cheapest one available....which was of course the way older V2 hardware that had been stuck in the supply chain for a while. Conversation was along these lines - Boss:"I can't return it , It's the same model", Me:"No it's not", followed by two unnecessary hours of effing about with upgrades and configuration to get them to even begin to 'play nicely' with each other.
Oh yeah - watch out for their implementation of 'Link Aggregation', either passive or active.
Thanks to Richard again for the donation of lots-of-ports-of Cisco gear for my home lab. Luxury in comparison!
Who give's the bad guys access to their router's web server?
"Multiple Netgear devices contain a stack buffer overflow in the httpd web server's handling of upgrade_check.cgi, which may allow for unauthenticated remote code execution with root privileges,"
Why would the router's web server be exposed to a remote network in the first place?