News: 1615485548

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

This Netgear SOHO switch has 15 – count 'em! – vulns, which means you need to upgrade the firmware... now

(2021/03/11)


Netgear has released a swathe of security and firmware updates for its JGS516PE Ethernet switch after researchers from NCC Group discovered 15 vulnerabilities in the device – including an unauthenticated remote code execution flaw.

The switch is vulnerable to nine high-severity vulns and a further five medium-rated ones, said NCC Group IT security consultant Manuel Ginés Rodriquez in a [1]damning blog post about his findings.

[2]

The critical vuln, an RCE ( [3]CVE-2020-26919 ), came about because firmware versions prior to 2.6.0.43 "failed to correctly implement access controls in one of its endpoints, allowing unauthenticated attackers to bypass authentication and execute actions with administrator privileges."

Rodriguez wrote that from the router's default login.html page "every section... could be used as a valid endpoint to submit POST requests being the action defined by the submitId argument." Ordinary low-privileged users could therefore execute system commands.

[4]

This opens the door for a malicious person to hijack your switch, perhaps installing malware on it to silently man-in-the-middle your internet connection. Small wonder NCC gave it a CVSSv3 score of 9.8, almost at the highest severity of 10.0.

On top of that was an active-by-default TFTP server running on the device which permitted the upload and execution of unsigned firmware updates, allowing anyone at all to upload potentially malicious updates to the switch even if they weren't aware of the RCE vuln ( [5]CVE-2020-35220 ).

If you own one of these 45 Netgear devices, replace it: Kit maker won't patch vulnerable gear despite live proof-of-concept code [6]READ MORE

"The uploaded file is being written directly into the image partition, overwriting the previous information before being validated," noted Rodriguez.

Netgear did not respond to a request for comment. The company has form for its product lines containing multiple severe vulnerabilities, as The Register found last year [7]when Netgear decided it wouldn't update the firmware for a swathe of vulnerable small office/home office routers – even though researchers had published live proof-of-concept code for exploits targeting the 40 devices.

In the company's defence it has published firmware updates for the JGS516PE switch [8]on its website . The current version is 2.6.0.48.

[9]

The firm, whose good reputation has taken a bit of a bashing in recent years, also came under fire from customers last year after they discovered that its latest managed switches [10]do not offer access to the full user interface unless you register them through the Netgear Cloud . ®

Get our [11]Tech Resources



[1] https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://cve.mitre.org/cgi-bin/cvename.cgi?name=

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35220

[6] https://www.theregister.com/2020/07/30/netgear_abandons_45_routers_vuln_patching/

[7] https://www.theregister.com/2020/07/30/netgear_abandons_45_routers_vuln_patching/

[8] https://www.netgear.com/support/product/JGS516PE.aspx#Security_CommonTopics

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YEqhCumeQdF3iOBC1IzWswAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2020/09/21/netgear_mandatory_registration_switches/

[11] https://whitepapers.theregister.com/

This is not "consumer" kit

Mike 137

Netgear used to produce excellent kit. Then we saw a split between commercial and consumer ranges, with the commercial stuff much less prone to bugs. Now that seems to have changed again, as this device is definitely aimed at the business market but obviously can't be trusted at all.

Who else is affected?

Dvon of Edzore

Firmware for such devices is often shared among multiple related products, including those from other vendors, because chipset makers generally provide reference designs and code libraries for the purchasers to brand with their product logos and other user interface customizations. This was seen last year when a broad swath of Netgear home routers were found vulnerable to a common set of vulnerabilities, as cited in the story.

Searching the CVE database for the similar JGS524PE, one finds four 2020 vulnerabilities shared by the JGS516PE, JGS524PE, JGS524Ev2, and GS116Ev2. Someone having any of these four sibling devices should press Netgear for answers.

Hmm, let's see

heyrick

Good company that made good products hijacked by bean counters that wanted to push costs down to maximise shareholder profit?

Something along those lines?

Press vendor for answers...

Jean Le PHARMACIEN

Good luck with that.

Keeping on top of vulns costs money and Netgear seemingly won't spend.

I used to have several of these models but sold them due to lack of confidence in updates (i.e. none)

Problem is, whom/which manufacturers who produce good kit can you trust (at a consumer/"pro-sumer" level)?

Re: Press vendor for answers...

new4u

I am happy with Draytek equipment - really reactive support, and as far as I understand generally safe products plus relatively good firmware maintenance. Also quick reaction in case there is a general issue - like KRACK.

Re: Press vendor for answers...

Jean Le PHARMACIEN

I've had Draytek AP 900s/902s which were good but I lacked the network management appliance (forget the model) so managing via http over a private VPN from 700 miles awsy was a pain...

Support was good when sn AP902 decided to curl up its 5ghz output - never did get it fixed - just dead even after multiple tftp firmware flashes

Using Unifi now - mainly because management at distance has been easier, UNC can be on your own hardware and I could run UVC cameras at same location on same hardware (yes. I know, Unifi Protect has complicated this)

No, please don't fix anything, Netgear!

Michael Hoffmann

I've been using an undocumented, unauthenticated endpoint for monitoring internals of some Netgear devices for years now. First time I found it, I facepalmed so hard I almost knocked out my own teeth, but then went "oh hey, this is convenient, just gotta keep it far, far away from the Internet".

(yes, I'm being facetious, but it's still true: it's treasure trove of info in there, so I thought I'd make use of it for my own devices)

Linux Drinking Game (Abridged)

With a group of friends, take turns reading articles about Linux from popular
media sources (Ziff-Davis AnchorDesk is recommended) or postings on Usenet (try
alt.fan.bill-gates). If the author says one of the things below, take a drink.
Continue until everyone involved is plastered.

- Linux will never go mainstream
- Any platform that can't run Microsoft Office [or some other Microsoft
"solution"] sucks
- Linux is hard to install
- Linux tech support is lacking
- No one ever got fired for choosing Microsoft
- Any OS with a command line interface is primitive
- Microsoft is an innovative company
- Could you get fired for choosing Linux?
- Linux was created by a bunch of snot-nosed 14 year old hackers with acne and
no life
- Security through obscurity is the way to go
- Linus and Unix are 70s technology while NT is 90s technology
- All Linux software must be released under the GPL
- Linux is a great piece of shareware