Netgear: & genie = 1 in the URL and you have access to each router

If something of Netgear in your home or somewhere else, it's probably time to upgrade the firmware... The manufacturing company has just released a tsunami of patches for a lot of models it manufactures that are affected.

Vulnerabilities were identified by Martin Rakhmanov Trustwave, The researcher spent more than a year chasing vulnerabilities in Netgear's firmware.Netgear

The have been released, and you'd do well to install them as soon as possible, before bots and botnets start exploiting them. Instructions on how to apply the updates are included in the company websites.

Let's see what happened:

About Netgear's 17 routers have remote URL bypasses. This means that any malicious user or malware can access your device's configuration page.

The most important thing is that anyone can gain access, without needing a password . How;

By simply adding the characters & genie = 1 at the end of the URL.

So very bad news for any portal that has remote configuration access enabled, as anyone in the can exploit the vulnerability and take over the router. So it can change DNS settings, redirect browsers to malicious sites and much more.

Do not wait: Directly upgrade your Netgear firmware.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).