NetGear Warns Users To Patch Recently Fixed Wi-Fi Router Bug (bleepingcomputer.com) 7
Netgear has fixed a high-severity vulnerability affecting multiple WiFi router models and advised customers to update their devices to the latest available firmware as soon as possible. BleepingComputer reports: The flaw impacts multiple Wireless AC Nighthawk, Wireless AX Nighthawk (WiFi 6), and Wireless AC router models. Although Netgear did not disclose any information about the component affected by this bug or its impact, it did say that it is a pre-authentication buffer overflow vulnerability. The impact of a successful buffer overflow exploitation can range from crashes following denial of service to arbitrary code execution, if code execution is achieved during the attack. Attackers can exploit this flaw in low-complexity attacks without requiring permissions or user interaction. In a security advisory published on Wednesday, Netgear said it "strongly recommends that you download the latest firmware as soon as possible." A list of vulnerable routers and the patched firmware versions can be found here.
Betagear (Score:1)
Re: (Score:1)
Re: (Score:2)
I agree that today it's starting to be problematic with all the different subscription and membership "services" where all you are is the product for them. Imagine that all those different signups ends up in the same database, which isn't hard because never expect those companies to actually manage the data themselves - it's "outsourced".
So far I did discover that I do have the R8000 and not the R8000P, but it's hard to tell if it's vulnerable or not. Either it's out of support or it's not vulnerable.
What r
Re: Betagear (Score:1)
The problem is buying Netgear in the first place. They've always shipped products with buggy firmware. I bought a print server that never worked as advertised they just kept sending me replacement units until they EOLd it out of warranty.
Naturally Netgear anything has never passed through my hands again.
This article is very late (Score:2)
Something must have changed in the wild, because I've had the patch for this on my device since late July 2022.
I do not understand the timing of this article.
Back up your config first! (Score:2)
I woke up to no wifi - turned out my Nighthawk had auto-updated last night and lost its config. I also noticed a lot of NETGEARxx SSIDs broadcasting - that's the SSID they use if they haven't been configured, so I bet that hit some other people too.
I just re-loaded my last saved config and it worked fine.
So:
1) Backup your config
2) Update the firmware
3) Restore the config only if necessary.
If it already updated itself and lost the config, well you can upload that
automated lead generation (Score:1)