Security News

Netgear Zero-Day Allows Full Takeover of Dozens of Router Models
2020-06-19 13:05

UPDATED. Researchers this week said they discovered an unpatched, zero-day vulnerability in firmware for Netgear routers that put 79 device models at risk for full takeover, they said. The flaw, a memory-safety issue present in the firmware's httpd web server, allows attackers to bypass authentication on affected installations of Netgear routers, according to two separate reports: One on the Zero Day Initiative by a researcher called "d4rkn3ss" from the Vietnam Posts and Telecommunications Group; and a separate blog post by Adam Nichols of cybersecurity firm Grimm.

Critical Netgear Bug Impacts Flagship Nighthawk Router
2020-03-04 18:58

Netgear is warning users of a critical remote code execution bug that could allow an unauthenticated attacker to take control of its Wireless AC Router Nighthawk hardware running firmware versions prior to 1.0.2.68. The critical vulnerability, tracked by Netgear as PSV-2019-0076, affects the company's consumer Nighthawk X4S Smart Wi-Fi Router first introduced in 2016 and still available today.

Netgear's routerlogin.com HTTPS cert snafu now has a live proof of concept
2020-02-12 12:52

An infosec researcher has published a JavaScript-based proof of concept for the Netgear routerlogin.com vulnerability revealed at the end of January. Through service workers, scripts that browsers run as background processes, Saleem Rashid reckons he can exploit Netgear routers to successfully compromise admin panel credentials.

Leaving your admin interface's TLS cert and private key in your router firmware in 2020? Just Netgear things
2020-01-20 21:23

Netgear left in its router firmware key ingredients needed to intercept and tamper with secure connections to its equipment's web-based admin interfaces. Specifically, valid, signed TLS certificates with private keys were embedded in the software, which was available to download for free by anyone, and also shipped with Netgear devices.

DoS Vulnerabilities Patched in NETGEAR N300 Routers
2019-09-13 09:49

A firmware update NETGEAR recently released for the N300 series routers addresses two denial-of-service (DoS) vulnerabilities found by security researchers at Cisco’s Talos group. Tracked as...

Register-Orbi-damned: Netgear account order irks infosec bods
2018-09-10 23:59

Marketing data collection opens potential security nightmare Netgear has irked some security pros by demanding people register accounts before they can use a mobile app to control their Orbi mesh routers.…

VPNFilter Malware Infects 500k Routers Including Linksys, MikroTik, NETGEAR
2018-05-23 16:48

Researchers warn of malware infecting 500,000 popular routers in a campaign mostly targeting the Ukraine, but also 54 other countries.

Flaws Affecting Top-Selling Netgear Routers Disclosed
2018-02-09 06:47

Security firm Trustwave has disclosed the details of several vulnerabilities affecting Netgear routers, including devices that are top-selling products on Amazon and Best Buy. read more

Netgear Fixes 50 Vulnerabilities in Routers, Switches, NAS Devices
2017-10-02 19:13

Netgear patches over a dozen vulnerabilities impacting its routers, switches and NAS devices.

Netgear Patches Over 50 Flaws in Routers, Switches, NAS Devices
2017-10-02 09:36

Netgear published more than 50 security advisories in the past two weeks to inform customers about the availability of patches for vulnerabilities affecting many of the company’s routers,...