Marty Chinn
Member
I know this got posted yesterday but with only one reply, it seems to have gone unnoticed so I'm posting it again with hopefully a better eye catching title since it's a huge backdoor. I know the Netgear Nighthawk R7000 is a widely used router around here and is often recommended and it's one of the affected ones.
https://www.wired.com/2016/12/ton-popular-netgear-routers-exposed-no-easy-fix/
Here's the link to the beta patched firmware.
http://kb.netgear.com/000036386/CVE-2016-582384
Here's also the link to the original thread which went unnoticed:
http://www.neogaf.com/forum/showthread.php?t=1324951
Andrew Rollins, a security researcher who also goes by Acew0rm, notified Netgear about the flaw on August 25, but says that the company never responded to him. After waiting more than three months, he went public with the vulnerability, and the Department of Homeland Securitys CERT group released an advisory about it on Friday. Its advice? Pull the plug.
Exploiting this vulnerability is trivial. Users who have the option of doing so should strongly consider discontinuing use of affected devices until a fix is made available, the CERT notice said. The flaw allows unauthenticated web pages to access the command-line and then execute malicious commands, which could lead to total system takeover.
After initially saying over the weekend that three products might be vulnerable, Netgear now confirms that eight of its router models (R6250, R6400, R6700, R7000, R7100LG, R7300, R7900, R8000) are affected, including three of the five most popular routers on Amazon. Netgear also declined to comment on why its taking so long to release a production-grade firmware update.We strive to earn and maintain the trust of those that use Netgear products for their connectivity, the company said in a statement.
https://www.wired.com/2016/12/ton-popular-netgear-routers-exposed-no-easy-fix/
Here's the link to the beta patched firmware.
http://kb.netgear.com/000036386/CVE-2016-582384
Here's also the link to the original thread which went unnoticed:
http://www.neogaf.com/forum/showthread.php?t=1324951