Started By
Message

Owners of Netgear R8000(X6), R7000(Nighthawk) or R6400 wifi routers, please read

Posted on 12/12/16 at 9:19 am
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 9:19 am
quote:

Bad news for consumers with Netgear routers: Two popular Netgear routers are vulnerable to a critical security bug that could allow attackers to run malicious code with root privileges.

Netgear's R7000 and R6400 routers, running current and latest versions of firmware, are vulnerable to arbitrary command injection attacks, though the number of users affected by the flaw is still unclear.

In an advisory published on Friday in Carnegie Mellon University's public vulnerability database (CERT), security researchers said that all an attacker needs to do is trick a victim into visiting a website that contains specially crafted malicious code to exploit the flaw.

As soon as the victim lands on the page, the malicious commands would execute automatically with root privileges on affected routers.

A working exploit leveraging the vulnerability has also been publicly released so that anyone can carry out attacks against the vulnerable routers.

Researchers warned that other router models might also be affected by the vulnerability, advising Netgear users to stop using the routers until a patch is released.


quote:

A working exploit leveraging the vulnerability has also been publicly released so that anyone can carry out attacks against the vulnerable routers.

Researchers warned that other router models might also be affected by the vulnerability, advising Netgear users to stop using the routers until a patch is released.

Your router could be compromised with no fixed release date for a patch. So, CERT strongly recommended Netgear users to "consider discontinuing use" of the affected routers until a patch is made available.

Hackers are increasingly targeting insecure, vulnerable routers with the purpose of making them part of nasty IoT botnets that are used to launch massive distributed denial-of-service (DDoS) attacks to knock online services offline.

Over a month ago, we saw Mirai Botnet taking entire Internet offline for few hours just by launching DDoS attacks (came from insecure IoT devices) against Dyn DNS service that crippled some of the world's biggest and most popular websites.

Just last week, nearly 1 Million users in Germany were also deprived of telephony, television, and Internet service after a supposed cyber-attack hijacked home broadband routers belonging to Deutsche Telekom.


Link to full article on The Hacking News

I own a Netgear R7000 ad I've been looking for a reason to buy a new router. I've been looking to getting either an Asus AC3100, Asus AC5300 (if I really want to go overboard) or a Netgear X6-AC3200.

Anyways, thought I would pass this along to the other owners of the Netgear R7000 or R6400 on this board.

ETA: Will be posting updates to OP as I or others find information (bear with me, I'm working from my phone because I forgot to pay my internet bill... good thing I guess? )

Update 1:
***Temporary Fix***

Currently known impacted Routers:
- Netgear R6400 "?" (AC1750)
- Netgear R7000 "Nighthawk" (AC1900)
- Netgear R8000 "X6" (AC3200)

Security Advisory from Netgear.com

CERT Vulnerability Report (linked in article)

Exploit Database entry (linked in article)
This post was edited on 12/12/16 at 6:14 pm
Posted by Will Cover
St. Louis, MO
Member since Mar 2007
38511 posts
Posted on 12/12/16 at 9:46 am to
Following.

I just bought (on Saturday) a Netgear R7000.

Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 10:02 am to
That sucks man. Talk about bad timing

Did you keep the receipt? If so, go exchange it.
Posted by meauxjeaux2
watson
Member since Oct 2007
60283 posts
Posted on 12/12/16 at 10:23 am to
I have the R7000 as well but do not have a computer hooked to it. Only use wifi for smart phones and gaming consoles and streaming media devices

LINK
Posted by WavinWilly
Wavin Away in Sharlo
Member since Oct 2010
8781 posts
Posted on 12/12/16 at 10:41 am to
well damn. I recommend the R7000 to everyone. I don't use it as my primary router anymore because it can't handle 1Gb WAN to LAN, but I have it hooked up as a VPN server. Guess I will need to pull it for now.
Posted by Layabout
Baton Rouge
Member since Jul 2011
11082 posts
Posted on 12/12/16 at 10:55 am to
quote:

I have the R7000 as well but do not have a computer hooked to it. Only use wifi for smart phones and gaming consoles and streaming media devices


Is the vulnerability limited to computers or can it be exploited by smart phones as well?
Posted by meauxjeaux2
watson
Member since Oct 2007
60283 posts
Posted on 12/12/16 at 10:56 am to
i'd like some clarification on this as well.
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 11:31 am to
I'm not sure. Neither the article or the cited links provide any insight into this. One would think they would have included this sort of information but obviously they didn't. The article suggests removal of the router all together (i.e. Use a different router) until the vulnerability is patched.
Posted by SATNIGHTS
Red Stick
Member since Jan 2008
2238 posts
Posted on 12/12/16 at 11:55 am to
X4 here. Hopefully it's not affected.
Posted by Carson123987
Middle Court at the Rec
Member since Jul 2011
66377 posts
Posted on 12/12/16 at 12:08 pm to
Yikes
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 12:19 pm to
You appear to be ok (keyword appear). Although don't be surprised if the X4 (R7500) is added to the list in the near future because in the link posted by meaux, this exploit includes the X6 (R8000) router so that model is out for me. Guess it's Asus or bust for me at the moment.
Posted by TeddyPadillac
Member since Dec 2010
25446 posts
Posted on 12/12/16 at 12:25 pm to
quote:

security researchers said that all an attacker needs to do is trick a victim into visiting a website that contains specially crafted malicious code to exploit the flaw


So don't watch porn until they get the patch. Easy enough.
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 12:30 pm to
quote:

So don't watch porn until they get the patch. Easy enough.


I can't fap to this.
Posted by Hu_Flung_Pu
Central, LA
Member since Jan 2013
22159 posts
Posted on 12/12/16 at 1:21 pm to
I have a R6700 Costco model. I wonder if this effects it.
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 1:27 pm to
To be honest, If you have a Netgear router, I'd pull it for the time being. It sucks but you don't want to take any chances.
Posted by Hu_Flung_Pu
Central, LA
Member since Jan 2013
22159 posts
Posted on 12/12/16 at 1:40 pm to
I'm unclear on what is going on with it. If I don't go to sketchy sites does it matter? I hardly use my computer on that router anyway. It's mainly for FireTV/Kodi and phones
Posted by Zappas Stache
Utility Muffin Research Kitchen
Member since Apr 2009
38652 posts
Posted on 12/12/16 at 2:51 pm to
So if I flash Tomato to it, which I plan on doing anyway, will that fix the problem?
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 3:02 pm to
quote:

So if I flash Tomato to it, which I plan on doing anyway, will that fix the problem?


I would think so because I think this is a firmware issue and not a hardware issue but I'm not 100% sure. I plan on flashing mine with either Tomato or DD-WRT regardless.
Posted by Hogkiller10
LP
Member since Jan 2010
1529 posts
Posted on 12/12/16 at 5:45 pm to
You can flash to the asus patch and be good to go or you can wait for them to release the fix.

Here is another "temp" fix for now. This is the easiest to apply to anyone that can type!

LINK
This post was edited on 12/12/16 at 5:53 pm
Posted by drewnbrla
The Pool is closed.
Member since Mar 2011
7839 posts
Posted on 12/12/16 at 6:11 pm to
Nice fricking find! Will it's temporary, it's better than nothing!
first pageprev pagePage 1 of 3Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram