This Netgear SOHO switch has 15 – count 'em! – vulns, which means you need to upgrade the firmware... now
- Reference: 1615485548
- News link: https://www.theregister.co.uk/2021/03/11/netgear_jgs516pe_switch_15_vulns/
- Source link:
The switch is vulnerable to nine high-severity vulns and a further five medium-rated ones, said NCC Group IT security consultant Manuel Ginés Rodriquez in a [1]damning blog post about his findings.
[2]
The critical vuln, an RCE ( [3]CVE-2020-26919 ), came about because firmware versions prior to 2.6.0.43 "failed to correctly implement access controls in one of its endpoints, allowing unauthenticated attackers to bypass authentication and execute actions with administrator privileges."
Rodriguez wrote that from the router's default login.html page "every section... could be used as a valid endpoint to submit POST requests being the action defined by the submitId argument." Ordinary low-privileged users could therefore execute system commands.
[4]
This opens the door for a malicious person to hijack your switch, perhaps installing malware on it to silently man-in-the-middle your internet connection. Small wonder NCC gave it a CVSSv3 score of 9.8, almost at the highest severity of 10.0.
On top of that was an active-by-default TFTP server running on the device which permitted the upload and execution of unsigned firmware updates, allowing anyone at all to upload potentially malicious updates to the switch even if they weren't aware of the RCE vuln ( [5]CVE-2020-35220 ).
If you own one of these 45 Netgear devices, replace it: Kit maker won't patch vulnerable gear despite live proof-of-concept code [6]READ MORE
"The uploaded file is being written directly into the image partition, overwriting the previous information before being validated," noted Rodriguez.
Netgear did not respond to a request for comment. The company has form for its product lines containing multiple severe vulnerabilities, as The Register found last year [7]when Netgear decided it wouldn't update the firmware for a swathe of vulnerable small office/home office routers – even though researchers had published live proof-of-concept code for exploits targeting the 40 devices.
In the company's defence it has published firmware updates for the JGS516PE switch [8]on its website . The current version is 2.6.0.48.
[9]
The firm, whose good reputation has taken a bit of a bashing in recent years, also came under fire from customers last year after they discovered that its latest managed switches [10]do not offer access to the full user interface unless you register them through the Netgear Cloud . ®
Get our [11]Tech Resources
[1] https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://cve.mitre.org/cgi-bin/cvename.cgi?name=
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35220
[6] https://www.theregister.com/2020/07/30/netgear_abandons_45_routers_vuln_patching/
[7] https://www.theregister.com/2020/07/30/netgear_abandons_45_routers_vuln_patching/
[8] https://www.netgear.com/support/product/JGS516PE.aspx#Security_CommonTopics
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2020/09/21/netgear_mandatory_registration_switches/
[11] https://whitepapers.theregister.com/
Who else is affected?
Firmware for such devices is often shared among multiple related products, including those from other vendors, because chipset makers generally provide reference designs and code libraries for the purchasers to brand with their product logos and other user interface customizations. This was seen last year when a broad swath of Netgear home routers were found vulnerable to a common set of vulnerabilities, as cited in the story.
Searching the CVE database for the similar JGS524PE, one finds four 2020 vulnerabilities shared by the JGS516PE, JGS524PE, JGS524Ev2, and GS116Ev2. Someone having any of these four sibling devices should press Netgear for answers.
Hmm, let's see
Good company that made good products hijacked by bean counters that wanted to push costs down to maximise shareholder profit?
Something along those lines?
Press vendor for answers...
Good luck with that.
Keeping on top of vulns costs money and Netgear seemingly won't spend.
I used to have several of these models but sold them due to lack of confidence in updates (i.e. none)
Problem is, whom/which manufacturers who produce good kit can you trust (at a consumer/"pro-sumer" level)?
Re: Press vendor for answers...
I am happy with Draytek equipment - really reactive support, and as far as I understand generally safe products plus relatively good firmware maintenance. Also quick reaction in case there is a general issue - like KRACK.
Re: Press vendor for answers...
I've had Draytek AP 900s/902s which were good but I lacked the network management appliance (forget the model) so managing via http over a private VPN from 700 miles awsy was a pain...
Support was good when sn AP902 decided to curl up its 5ghz output - never did get it fixed - just dead even after multiple tftp firmware flashes
Using Unifi now - mainly because management at distance has been easier, UNC can be on your own hardware and I could run UVC cameras at same location on same hardware (yes. I know, Unifi Protect has complicated this)
No, please don't fix anything, Netgear!
I've been using an undocumented, unauthenticated endpoint for monitoring internals of some Netgear devices for years now. First time I found it, I facepalmed so hard I almost knocked out my own teeth, but then went "oh hey, this is convenient, just gotta keep it far, far away from the Internet".
(yes, I'm being facetious, but it's still true: it's treasure trove of info in there, so I thought I'd make use of it for my own devices)
This is not "consumer" kit
Netgear used to produce excellent kit. Then we saw a split between commercial and consumer ranges, with the commercial stuff much less prone to bugs. Now that seems to have changed again, as this device is definitely aimed at the business market but obviously can't be trusted at all.