Security News > 2021 > July > Critical, Exploitable Flaws in NETGEAR Router Firmware

Critical, Exploitable Flaws in NETGEAR Router Firmware
2021-07-01 14:49

Security researchers at Microsoft are flagging multiple gaping security holes in firmware shipped on NETGEAR routers, warning that exploitation could lead to identity theft and full system compromise.

The three vulnerabilities, rated critical by NETGEAR, affect the firmware on NETGEAR DGN-2200v1 series routers.

According to Microsoft's Jonathan Bar Or, exploits for these firmware flaws can compromise a network's security, opening the gates for attackers to roam untethered through an entire organization.

"We noticed a very odd behavior: a device owned by a non-IT personnel was trying to access a NETGEAR DGN-2200v1 router's management port. The communication was flagged as anomalous by machine learning models, but the communication itself was TLS-encrypted and private to protect customer privacy, so we decided to focus on the router and investigate whether it exhibited security weaknesses that can be exploited in a possible attack scenario," Bar Or explained.

Firmware security has emerged as a front-burner issue recently with a recent Microsoft-sponsored study claiming a whopping 80 percent of businesses reported "At least one firmware attack" in the past two years but only 30 percent allocated any budget spend on firmware protection.

Microsoft has made firmware and IOT security a priority recently, with two strategic acquisitions - Refirm Labs and CyberX - meant to shore up its ability to pinpoint and fix weak links at the firmware layer.


News URL

http://feedproxy.google.com/~r/securityweek/~3/bnCCCoLlY0M/critical-exploitable-flaws-netgear-router-firmware

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Netgear 502 8 474 462 149 1093