Vulnerably above Netgear's 30 routers

Are you using a Netgear router? Researchers have discovered a very serious security gap that affects hundreds of thousands of Netgear devices.

The security company Trustwave reports that the it essentially allows attackers to exploit the password recovery system του δρομολογητή (router) για να παρακάμψουν τον έλεγχο ταυτότητας και χρησιμοποιώντας διαπιστευτήρια διαχειριστή, καταφέρνουν να έχουν πλήρη πρόσβαση στη συσκευή και τις ρυθμίσεις της.Netgear

What is particularly worrying is that the security gap occurs in at least 31 different Netgear models leaving more than one million users open to attacks.

Even more worrying is the fact that these devices could in some cases be hacked remotely. As Trustwave researcher Simon Kenin explains, every router that has the remote management enabled is vulnerable to hack.

Note that remote management is disabled by default on most devices, and the company says it has found more than 10 routers that have been compromised, but the actual number could be "over a million."

Kenin also warns that anyone with physical access to a defective router from Netgear can abuse its defensive mechanisms and gain access to the device by adding the router to botnets.

"The vulnerability could be exploited by a remote attacker if remote management is enabled. By default the function is not activated. However, anyone with physical access to a network with a vulnerable router can take advantage of it locally, "said the researcher.

"This includes public Wi-Fi areas, such as cafes and libraries that use vulnerable equipment."

Trustwave reported the security gap in National Vulenrability Database. The Netgear confirmed also the defect with a publication on its website, giving the full list of affected models:

  • R8500
  • R8300
  • R7000
  • R6400
  • R7300DST
  • R7100LG
  • R6300v2
  • WNDR3400v3
  • WNR3500Lv2
  • R6250
  • R6700
  • R6900
  • R8000
  • R7900
  • WNDR4500v2
  • R6200v2
  • WNDR3400v2
  • D6220
  • D6400
  • C6300 (firmware released to ISPs)

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).