Netgear router owners please update your firmware

Back in December a vunerability has been exposed on Netgear routers. Most routers already had firmware updates available and most of them can be updated. However Both Netgear and Cert now again issue a warning, please up update your firmware ASAP.



The problem is that due to a security issue anyone can login to your router as the admin password can be read out from the web-side. All information and firmware links can be found here.

If your router is not in the list just yet, please simply disable remote management. Which properly is an advise for any router in existence. 

Firmware fixes are currently available for the following affected devices. To download the firmware release that fixes the password recovery vulnerability, visit the firmware release page for instructions:

NETGEAR has also released firmware that fixes the web password recovery vulnerability for the following cable modem router:

For cable products like the C6300, new firmware is released by your Internet service provider after NETGEAR releases it to them. The firmware fix for the C6300, firmware version 2.01.18, has been released to all service providers. Until your service provider releases the firmware fix to you, NETGEAR strongly recommends that you use the workaround procedure explained in this article. To see your C6300’s current firmware version, visit the following knowledge base article and follow the instructions: How do I view the firmware version of my cable modem or modem router?.

NETGEAR has tested the following devices and confirmed that they are not affected by the web password recovery vulnerability:

For the following affected products, NETGEAR recommends using the workaround procedure explained in this article.

Router Model and Firmware Version:

DSL Gateway Model and Firmware Version:

If your affected product does not have a firmware fix available, NETGEAR strongly recommends that you follow this workaround procedure to remediate the vulnerability:

  1. Manually enable the password recovery feature on your device.
    For more information, visit Configuring router administrative password recovery.
  2. Ensure that remote management is disabled.
    Remote management is disabled by default. For more information, check the user manual for your product, which is available from http://www.netgear.com/support/.

The potential for password exposure remains if you do not complete both steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.

Netgear router owners please update your firmware



Printed from: https://www.guru3d.com/story/netgear-router-owners-please-update-your-firmware/