Many Netgear router models contain serious RCE security holes
If you are using one of the following Netgear router models, you should immediately update to the latest firmware.
Network equipment maker Netgear has just released a patch for a critical vulnerability in some router models. Exploiting this vulnerability, hackers can deploy remote code execution (RCE) attacks to take control of the affected system.
This vulnerability is assigned code CVE-2021-40847 and affects the following router models:
- R6400v2 (patched with firmware version 1.0.4.120)
- R6700 (patched with firmware version 1.0.2.26)
- R6700v3 (patched with firmware version 1.0.4.120)
- R6900 (fixed with firmwaren 1.0.2.26)
- R6900P (patched with firmware version 3.3.142_HOTFIX)
- R7000 (patched with firmware version 1.0.11.128)
- R7000P (patched with firmware version 1.3.3.142_HOTFIX)
- R7850 (patched with firmware version 1.0.5.76)
- R7900 (patched with firmware version 1.0.4.46)
- R8000 (patched with firmware version 1.0.4.76)
- RS400 (patched with firmware version 1.5.1.80)
According to GRIMM security researcher Adam Nichols, the vulnerability resides in Circle, a third-party component in the firmware. It provides parental control features in Netgear devices.
More dangerously, the problem is related to Circle's update mechanism (deamon), which is enabled by default even if the router has not been set up to limit access time. This leads to hackers being able to execute RCE as root through Man-in-the-Middle (MitM) attack.
Update daemon connects Circle and Netgear together to find and load updates to the filter database. However, neither side is certified and downloads using the HTTP protocol. Therefore, hackers can break into the connection to install malicious files.
To ensure safety, Netgear recommends that users immediately update to the latest firmware versions.
You should read it
- Top 5 best Netgear routers today
- How to Login to Netgear Router
- NETGEAR Orbi review: One of the most powerful mesh router
- How to turn off SIP ALG on Netgear router
- How to set up Port Forwarding on Netgear router
- 8 best 802.11n routers in 2018
- List NETGEAR router default password
- Netgear router not working? Here's how to fix it!
- Enable remote management on NETGEAR router
- How to set up and configure DDNS on Netgear router
- Detecting security holes that cause a series of D-Link VPN routers to be remotely attacked
- Review NETGEAR Nighthawk R7000 AC1900: Leading dual band router
Maybe you are interested
Microsoft tests a Start menu interface similar to iOS How to Get More Results Out of Your Online Education Easily What to Look For In a Quality Online Learning Platform Equipment can replace smartphones, TVs Top 5 real-time voice changing software for Skype, Discord, Steam 2020 Online corner: Teachers use VR to teach math in the game Half Life: Alyx