Personal computing discussed

Moderators: renee, Steel, notfred

 
ludi
Lord High Gerbil
Topic Author
Posts: 8646
Joined: Fri Jun 21, 2002 10:47 pm
Location: Sunny Colorado front range

Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Wed Dec 14, 2016 12:33 pm

Heads up -- if you're using a Netgear Nighthawk R8XXX, R7XXX, or R6XXX series router and missed the news late last week of a remote exploit via the device's internal configuration webserver, double-check your model number to see if your unit is affected, and if a firmware update is available.

https://www.kb.cert.org/vuls/id/582384
http://arstechnica.com/security/2016/12 ... r-routers/
http://hothardware.com/news/netgear-dep ... le-routers

HotHardware wrote:
What’s interesting is that in addition to the three above routers that we know are susceptible to the remote exploit, Netgear revealed that there are actually 8 additional models that are affected. These include the R6250, R6700, R6900, R7100LG, R7300, R7900, D6220 and D7000.

In the mean time, Netgear has issue beta firmware for the following five models — R6250, R6400, R6700, R7000 and R8000 — which “has not been fully tested and might not work for all users”. Additional affected routers will receive beta firmware updates over the next few days.

Also, as a temporary fix, here's a way to use the exploit to shut down the vulnerable process for the remainder of the current session:
http://www.sj-vs.net/a-temporary-fix-fo ... 0-routers/
Abacus Model 2.5 | Quad-Row FX with 256 Cherry Red Slider Beads | Applewood Frame | Water Cooling by Brita Filtration
 
techguy
Gerbil XP
Posts: 404
Joined: Tue Aug 10, 2010 9:12 am

Re: Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Wed Dec 14, 2016 1:08 pm

Been running DD-WRT on my Nighthawk since day one (bought it the week it came out) and ran the test to determine whether or not my router is vulnerable - came up clean.  I'm not saying this is universally true, there are reports that DD-WRT is susceptible as well but at least in my case it is not.
 
ludi
Lord High Gerbil
Topic Author
Posts: 8646
Joined: Fri Jun 21, 2002 10:47 pm
Location: Sunny Colorado front range

Re: Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Wed Dec 14, 2016 7:04 pm

Yeah, the exploit seems to be specific to Netgear's firmware implementation on these particular models, so a third-party ROM may be fine.  Doesn't hurt to check any other model or firmware, though, and if it responds positively to the command then there's likely a problem that needs to be addressed.
Abacus Model 2.5 | Quad-Row FX with 256 Cherry Red Slider Beads | Applewood Frame | Water Cooling by Brita Filtration
 
liquidsquid
Minister of Gerbil Affairs
Posts: 2661
Joined: Wed May 29, 2002 10:49 am
Location: New York
Contact:

Re: Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Tue Jan 17, 2017 5:36 pm

I have the D7000 at home, and out of the box it doesn't appear to be vulnerable. Of course it is only a few months old now, so it may have later firmware than some.
 
Flying Fox
Gerbil God
Posts: 25690
Joined: Mon May 24, 2004 2:19 am
Contact:

Re: Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Tue Jan 17, 2017 5:40 pm

My R7000 has an updated firmware that Netgear said addresses the issue: http://kb.netgear.com/000036470/R7000-F ... on-1-0-7-6
The Model M is not for the faint of heart. You either like them or hate them.

Gerbils unite! Fold for UnitedGerbilNation, team 2630.
 
DancinJack
Maximum Gerbil
Posts: 4494
Joined: Sat Nov 25, 2006 3:21 pm
Location: Kansas

Re: Netgear Nighthawk R8XXX, R7XXX, R6XXX exploit - get your patch!

Tue Jan 17, 2017 5:42 pm

i7 6700K - Z170 - 16GiB DDR4 - GTX 1080 - 512GB SSD - 256GB SSD - 500GB SSD - 3TB HDD- 27" IPS G-sync - Win10 Pro x64 - Ubuntu/Mint x64 :: 2015 13" rMBP Sierra :: Canon EOS 80D/Sony RX100

Who is online

Users browsing this forum: No registered users and 21 guests
GZIP: On