NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

lenl's avatar
lenl
Initiate
Sep 20, 2019
Solved

Netgear Nighthawk M1 vulnerability

When will Netgear release a solution / fix for the Netgear Nighthawk M1 vulnerability as mentioned in the link below ?

VulDB 140070 · CVE-2019-14527
Netgear Nighthawk M1 prior 12.06.03 Web Interface System Command privilege escalation
https://vuldb.com/?id.140070

5 Replies

  • Upgrading to version 12.06.03 eliminates this vulnerability.

    • lenl's avatar
      lenl
      Initiate

      But the Nighthawk M1 says there is no new firmware update :smileysad:
      Is there a way to manual download new firmware ?

      • sena71's avatar
        sena71
        Tutor

        lmaooo are you sure about that? then explain to me how im able to force a telnet session with the internal linux/busybox OS? smh you guys couldn't even be bothered to change the root password from the default "oelinux123"