• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.
  • The Politics forum has been nuked. Please do not bring political discussion to the rest of the site, or you will be removed. Thanks.

HUGE exploit in Netgear Nighthawk and other routers, accessed by browsing the web

Status
Not open for further replies.

Marty Chinn

Member
Jun 6, 2004
31,449
0
1,585
I know this got posted yesterday but with only one reply, it seems to have gone unnoticed so I'm posting it again with hopefully a better eye catching title since it's a huge backdoor. I know the Netgear Nighthawk R7000 is a widely used router around here and is often recommended and it's one of the affected ones.

Andrew Rollins, a security researcher who also goes by Acew0rm, notified Netgear about the flaw on August 25, but says that the company never responded to him. After waiting more than three months, he went public with the vulnerability, and the Department of Homeland Security’s CERT group released an advisory about it on Friday. Its advice? Pull the plug.

“Exploiting this vulnerability is trivial. Users who have the option of doing so should strongly consider discontinuing use of affected devices until a fix is made available,” the CERT notice said. The flaw allows unauthenticated web pages to access the command-line and then execute malicious commands, which could lead to total system takeover.

After initially saying over the weekend that three products “might be vulnerable,” Netgear now confirms that eight of its router models (R6250, R6400, R6700, R7000, R7100LG, R7300, R7900, R8000) are affected, including three of the five most popular routers on Amazon. Netgear also declined to comment on why it’s taking so long to release a production-grade firmware update.”We strive to earn and maintain the trust of those that use Netgear products for their connectivity,” the company said in a statement.

https://www.wired.com/2016/12/ton-popular-netgear-routers-exposed-no-easy-fix/

Here's the link to the beta patched firmware.

http://kb.netgear.com/000036386/CVE-2016-582384

Here's also the link to the original thread which went unnoticed:

http://www.neogaf.com/forum/showthread.php?t=1324951
 

99Luffy

Slow in the head
Sep 10, 2016
1,942
268
450
Their response is terrible. Thats enough to stop me from ever buying a netgear product.
 

newshinycd

Member
May 29, 2013
950
0
400
Ha. I bought a new router last year, and I got some shit from coworkers because I went with an Asus router instead of Nighthawk.
Looks like they'll be eating crow tonight.
 

WorldStar

Banned
Jan 15, 2013
6,737
0
0
Ha. I bought a new router last year, and I got some shit from coworkers because I went with an Asus router instead of Nighthawk.
Looks like they'll be eating crow tonight.
The nighthawk is generally considered one of the best routers out there

Which is why this is so surprising
 

Audioboxer

Member
May 11, 2010
21,939
11
820
UK
Terrible response time from Netgear :( Just updated my R7000. I use it for wireless (piggybacks off another modem for connecting to Sky) and because I have a 5TB hard drive attached for media.
 

Magnus

Member
Jun 13, 2004
18,390
0
1,555
36
Toronto, Canada
Damn it, ours is the R7000. My boyfriend paid a buttload for that router too.

How serious is this really? Like, do I need to actually unplug and stop using the thing today?
 

Gurgelhals

Member
Oct 31, 2013
1,300
0
0
Switzerland
There's a reason why people should either use these things with some third-party open source firmware such as DD-WRT or switch over to prosumer-grade stuff such as Ubiquiti altogether.

A router is usually sitting at what is by far the most vulnerable spot of every home network. This fact alone should make you not want to run them on your run-of-the-mill consumer-grade software where keeping development costs as low as possible always trumps concerns about security and stability.
 

pestul

Member
Jun 13, 2004
10,506
0
0
Okay, so the survey company I do tech support for uses the R6300.. it's not on the list of effected routers, but I don't trust them.
 

RS4-

Member
Feb 8, 2009
18,320
2
0
Is it one of the best because of these backdoors :eek:

Almost bought one last year, got the Archer instead.
 

Marty Chinn

Member
Jun 6, 2004
31,449
0
1,585
Damn it, ours is the R7000. My boyfriend paid a buttload for that router too.

How serious is this really? Like, do I need to actually unplug and stop using the thing today?

Get the beta patched firmware. The link is in the OP.
 

Syriel

Member
Sep 21, 2009
9,607
1
905
So is this a backdoor or an NSA thing?

This is more of an engineering oops thing. There's no reason the web server should be running commands as an admin like that.

Damn it, ours is the R7000. My boyfriend paid a buttload for that router too.

How serious is this really? Like, do I need to actually unplug and stop using the thing today?

Anyone on your network can run any CLI commands they choose on the router.
 

TwoDurans

"Never said I wasn't a hypocrite."
Apr 23, 2011
4,691
1,042
1,105
Wait, wait, wait. People own Netgear routers and don't use dd-wrt?
 

Belker

Member
Dec 2, 2016
1,019
13
285
I had no idea this was a problem. Thanks for sharing the info. I've updated my router with the beta patch and tweeted a link to the article.
 

Dr. Zoidberg

Member
Nov 6, 2004
8,239
31
1,300
Well shit. I've been very happy with my R7000 since I've had it. My co-worker got the oft-recommended ASUS and has had a lot of problems. I guess it's my turn now. I'll install the beta firmware tonight. I've dealt with DD-WRT before and liked it, so that's another possibility.
 

Marty Chinn

Member
Jun 6, 2004
31,449
0
1,585
How would any hacker know one has such a router?

They wouldn't. They gain access by you going to a website. When you connect to that website, it can then send commands via that exploit to your router and gain access. So they don't come to you, you go to them without realizing it because all you did was browse the web.
 

CDX

Member
May 31, 2012
2,756
0
0
People have a router capable of putting DD-WRT, Tomato, or Open-WRT or some other firmware on it, BUT they just keep the manufactures firmware on it?

I find that odd, because It seems like in my circle of friends, nearly everybody has one of those firmwares listed above on their router.

But I guess now that I think about it, it shouldn't be odd that most will just stick with whatever firmware the manufacturer gives them. That's probably what the vast majority do.
 

jstripes

Banned
Dec 9, 2012
13,478
1
0
People have a router capable of putting DD-WRT, Tomato, or Open-WRT or some other firmware on it, BUT they just keep the manufactures firmware on it?

I find that odd, because It seems like in my circle of friends, nearly everybody has one of those firmwares listed above on their router.

But I guess now that I think about it, it shouldn't be odd that most will just stick with whatever firmware the manufacturer gives them. That's probably what the vast majority do.

Does your circle of friends happen to be tech savvy?

Most people don't even know you can update the manufacturer's firmware.
 
Status
Not open for further replies.