Microsoft warns of serious vulnerabilities in Netgear's DGN2200v1 router
- Reference: 1625161513
- News link: https://www.theregister.co.uk/2021/07/01/microsoft_netgear_security_advisory_dgn2200v1/
- Source link:
Unveiled by the company at the Consumer Electronics Show back in 2010, Netgear's DGN2200 is an ADSL modem-router combo box with, the company promised at the time, security features including "live parental controls, firewall protection, denial-of-service (DoS) attack prevention, [and] intrusion detection and prevention (IDS)."
Sadly, one thing didn't make the list: functional authentication. As a result, it's possible for remote attackers to take over the router at any time - as discovered by members of the Microsoft 365 Defender Research Team.
[1]
"We discovered the vulnerabilities while researching device fingerprinting in the new device discovery capabilities in Microsoft Defender for Endpoint," the research team said. "We noticed a very odd behaviour: a device owned by a non-IT personnel was trying to access a NETGEAR DGN2200v1 router's management port.
[2]
[3]
"The communication was flagged as anomalous by machine learning models, but the communication itself was TLS-encrypted and private to protect customer privacy, so we decided to focus on the router and investigate whether it exhibited security weaknesses that can be exploited in a possible attack scenario."
The answer, it turns out, is yes - and how. The three core vulnerabilities discovered by Microsoft, rated high-to-critical severity with CVSS scores ranging from 7.1 to 9.4, have been described in no lesser terms [4]than "opening the gates for attackers to roam untethered through an entire organisation."
[5]
The core issue behind the vulnerabilities is an authentication bypass flaw, the result of sloppy coding which makes it possible to access any resource on the router simply by including a substring in an HTTP GET request.
Once exploited, further vulnerabilities allow for security credentials - both those for the router and those for its WAN-side network connection - to be retrieved.
This isn't the first time Netgear has been caught with its security pants down, either - nor even the first this year. Back in March the NCC Group warned of [6]15 serious vulnerabilities in the Netgear JGS516PE Ethernet switch, its devices were implicated as being vulnerable to [7]the DNSpooq attack , and in February SonicWall fingered the DGN1000 and DGN2200 as [8]under active attack from vulnerabilities very similar to those discovered by Microsoft - the patch for which apparently failed to take.
[9]
"Third-party routers are often the way to go to own more control, but it doesn’t always mean they are bulletproof," Jake Moore, cybersecurity expert at ESET UK, told The Register .
"Although it would be worst-case scenario that any connected devices were to be attacked, this highlights that people must stay alert to such threats and to keep on top of patching all devices. And, of course, it is recommended to download and update to the latest firmware for this Netgear router to protect your network."
More details on the vulnerabilities are available on the [10]Microsoft blog , while instructions on upgrading the firmware to the fixed v1.0.0.60 release are on the [11]Netgear website .
Netgear, which in its partial defence has voluntarily patched the issues and released a firmware update for what is now an 11-year-old product, was approached for comment. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YN46-9X1lI35ERHHODMJiQAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN46-9X1lI35ERHHODMJiQAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YN46-9X1lI35ERHHODMJiQAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://techcommunity.microsoft.com/t5/security-compliance-and-identity/new-blog-post-microsoft-finds-new-netgear-firmware/td-p/2503214
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN46-9X1lI35ERHHODMJiQAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/03/11/netgear_jgs516pe_switch_15_vulns/
[7] https://www.theregister.com/2021/01/20/dns_cache_poisoning/
[8] https://securitynews.sonicwall.com/xmlpost/attackers-actively-targeting-vulnerable-netgear-dgn-devices/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YN46-9X1lI35ERHHODMJiQAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/
[11] https://kb.netgear.com/000062646/Security-Advisory-for-Multiple-HTTPd-Authentication-Vulnerabilities-on-DGN2200v1
[12] https://whitepapers.theregister.com/
Re: Ouch!
It's a ten year old design so the manufacturer probably stopped worrying about the code about 8 years ago and it probably hasn't been updated since then. Bad code is profitable ... time to buy a new router.
Re: Ouch!
Given how much developers are paid, why would they care?
I've had a dim view of Netgear since about 2008.
They may have improved since then.
I bought one of their routers. The specs were impressive, reviews found the performance was impressive.
Once I had the thing, I found two issues.
Firstly, and this unlike the second issue is rather nebulous, I've lot of experience with large bodies of unmaintainable C code and the UI to configure the device *totally* gave me that vibe. The options, the ways thing were arranged, interacted - it did not feel good.
Secondly, and this to me was the give-away, upgrading the firmware wiped all the settings, *and it was not possible to load saved settings from a previous version of the firmware*.
Settings should of course be saved in something like XML or what-have-you, and you can then load them, parse them, and get as much sane information from them as you can. Not being able to do so means settings were being saved a binary blob, which combined with my bad feelings about the whole thing in the first place. It also meant upgrading the firmware then involved 15 minutes of configuration work (there were a lot of options).
Over the years since then I've noticed quite a few stories of the most basic security blunders, although in fairness you can say that pretty much about all router vendors.
The consumer brand networking gear is hot garbage
D-Link, Netgear, it doesn't matter they are all unfit for purpose. Home routers are like home AV software. Sad thing is that the small office crap is also terrible, but also paradoxically 4x as expensive.
The whole market segment is ripe for a pitch invasion. Its gotten bad enough that people have started building their own out of a SFF PC that has more than one network port. Most will run circles around the consumer gear to, and can auto update themselves to boot.
Re: The consumer brand networking gear is hot garbage
Their higher end stuff is no better. I'm no security researcher but even I figured out how to get root access through their telnet interface on the SRX5308 a few years back. It was enough to allow me to flash OpenWRT onto it, despite not being supported by the distro at all, though I never did get the weird network hardware working properly. I was going to report the issue but I realised they'd already fixed it in a subsequent firmware update, probably only by accident though, as they'd changed much of the software stack.
Netgear is like IE
It's good enough to download OpenWRT, like IE is good enough to download Chrome.
Ouch!
How much code do they replicate from device to device, or do they write unique bad code for each one? I want network device code to be better than what I write as it is exposed to the world.