Netgear router flaws exploitable with authentication ... like the default creds on Netgear's website
- Reference: 1638552612
- News link: https://www.theregister.co.uk/2021/12/03/netgear_router_flaws_patched/
- Source link:
The vulns rely on authenticated access to affected devices so aren't an immediate threat. They do, however, allow someone with remote access to the router to pwn the device's underlying OS, threatening the security of data passing through the router.
Helpfully, Netgear itself publishes default login credentials for "most" of its products [1]on its website . If you haven't been into your Netgear router's admin panel and changed these default creds, you're at increased risk.
[2]
"This kind of command injection also adds persistence which means even if the router is restarted or updated, the vulnerability can persist," said Immersive Labs in [3]a blog post about its findings.
[4]
[5]
Affected router and Wi-Fi extender models, according to Netgear's own patch notes, are:
D7800 fixed in firmware version 1.0.1.66
EX2700 fixed in firmware version 1.0.1.68
WN3000RPv2 fixed in firmware version 1.0.0.90
WN3000RPv3 fixed in firmware version 1.0.2.100
LBR1020 fixed in firmware version 2.6.5.20
LBR20 fixed in firmware version 2.6.5.32
R6700AX fixed in firmware version 1.0.10.110
R7800 fixed in firmware version 1.0.2.86
R8900 fixed in firmware version 1.0.5.38
R9000 fixed in firmware version 1.0.5.38
RAX10 fixed in firmware version 1.0.10.110
RAX120v1 fixed in firmware version 1.2.3.28
RAX120v2 fixed in firmware version 1.2.3.28
RAX70 fixed in firmware version 1.0.10.110
RAX78 fixed in firmware version 1.0.10.110
XR450 fixed in firmware version 2.3.2.130
XR500 fixed in firmware version 2.3.2.130
XR700 fixed in firmware version 1.0.1.46
Immersive said it had found a third exploitable vuln disclosing the device's serial number, which is used in Netgear's password reset process as an authentication measure.
"Netgear strongly recommends that you download the latest firmware as soon as possible," said Immersive.
[6]Dang vaccines dented our bottom line in the connected home sector, says Netgear
[7]Microsoft warns of serious vulnerabilities in Netgear's DGN2200v1 router
[8]This Netgear SOHO switch has 15 – count 'em! – vulns, which means you need to upgrade the firmware... now
[9]Before you buy that managed Netgear switch, be aware you may need to create a cloud account to use its full UI
Immersive's Kev Breen, director of cyber threat research, said although these vulns rely on having a valid username and password combination for an affected device, that isn't an automatic reason for shrugging one's shoulders: "There is still a valid threat surface and whilst it remains in the realms of 'Hackers Could' it is always important when considering security vulnerabilities to look past the traditional exploit methods and put yourself in the shoes of an attacker. How could they abuse this?"
With Britain making [10]moves to ban default admin credentials this kind of problem should decrease in future.
On the flip side, there are already millions of routers in use today which don't comply with these proposed new regulations – so these kinds of vulns will continue to persist for a few years yet. ®
Get our [11]Tech Resources
[1] https://kb.netgear.com/1148/What-are-the-default-user-interface-passwords-for-NETGEAR-devices
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yaqhoyv73Z2ZMr8mRzuDqgAAAUY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.immersivelabs.com/resources/blog/netgear-vulnerabilities-could-put-small-business-routers-at-risk/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yaqhoyv73Z2ZMr8mRzuDqgAAAUY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yaqhoyv73Z2ZMr8mRzuDqgAAAUY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/07/22/netgear_q2_2021/
[7] https://www.theregister.com/2021/07/01/microsoft_netgear_security_advisory_dgn2200v1/
[8] https://www.theregister.com/2021/03/11/netgear_jgs516pe_switch_15_vulns/
[9] https://www.theregister.com/2020/09/21/netgear_mandatory_registration_switches/
[10] https://www.theregister.com/2021/12/02/psti_bill_phoenixing_dcms_response/
[11] https://whitepapers.theregister.com/
Lizzie Borden bought a Mac
Learned to code and
Hack Hack Hack
Alan Turing hacked the enigma machine way before RS232 was developed.
Hacking has been around since the Stone Age when some caveman took a Maypole, sharpened one end and javelined a wooly mammoth.
Bombe
"Alan Turing hacked the enigma machine"
Part brute-force attack, part dictionary "attack" (really test/analysis of parameter combinations, if I understand correctly).
Linksys?
A couple of years ago I bought a retail Linksys router. By far the easiest way to configure said router was to do the setup using a Linksys "cloud" password, and then doing the configuration via this handy "cloud" facility. (In fact, doing the configuration with a laptop, a CAT5 cable and NO INTERNET proved to be very difficult....I wonder why!)
The alleged "benefit" of this scheme was that I could manage my router (by smartphone) from the beach in Brazil. But I did wonder at the time if it allowed anyone who hacked the Linksys "cloud" to manage my LAN (also from the beach in Brazil).
I passed.....did a factory reset and boxed up the router and gave it to the local charity shop.
I mention this here because I wonder if retail routers are hackable from the "cloud" services which manufacturers kindly provide? No physical access needed!
Just saying!
A basic approach
Buying a device like this and connecting it directly to the Internet is a mistake - it's not just Netgear routers, this applies to anything you setup The only moderately safe connection is to use it on your local network so that its' Internet communications flow through a firewall - so most of the time the Internet does not see it but all the users have access (if you create a firewall rule allowing this). The device is still hackable if someone gets the wireless password or you support a guest access but this is only local folk, not a few billion people attempting to hack you.
The world needs to be reformatted.
So many vulnerabilities like this are normal - devices are built to be easy to use, device "security" is just a "feature" - I never saw anything hacked like this back when I had to access devices via an RS232 connection to run administrative setups. I see so much stuff like this, high speed internet access helps too - I'm only seeing about 200 administrative login attempts an hour on the mail-server today, but never saw any back when the access speed was 9600 baud and there were very few spam emails and no malware deliveries either.
We need to fix these problems by preventing the problems, not just adding a new feature like having the router text your phone when you need to log into it - that's just a security feature that will be hacked.