Security12.02.2018

Multiple security flaws found in Netgear routers

Netgear R7000 Nighthawk AC1900

Trustwave has issued an advisory on security vulnerabilities in Netgear routers which have been patched in firmware updates.

The bugs affect 17 router models, including the Netgear R8500 Nighthawk X8, running firmware 1.0.2.86 or earlier.

The security flaws were:

  • Routers let you read any file from the device, provided the path to the file is known.
  • Authentication bypass – trivial and affects all 17 routers.
  • Command injection on some routers after authentication.
  • Chained attack command injection – anyone can run commands as root by exploiting several vulnerabilities in sequence.
  • Run commands as root when WPS is activated – 6 products affected.

Trustwave commended Netgear for its responsive and communicative PSIRT team.

Patches for the issues above are available from Netgear.

Now read: Netgear unveils gaming router with DDoS protection

Show comments

Latest news

More news

Trending news

Poll

If you could have only one e-commerce marketplace subscription service, which would you choose?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter