NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
dread99a
Dec 21, 2021Tutor
Security concerns GS728TPv2 with FW v6.0.10.5
Updated my GS728TPv2 with FW v6.0.10.5 and noticed some serious security issues. 1. Though SSH has now been added to the switch.... SSH is missing in Security -> Access control section. HTTP, HTT...
dread99a
Jul 11, 2022Tutor
Well Netgear's support response is mostly incorrect. Security issues remain with FW v6.10.10.
1. If Telnet & SSH are disabled in the WebGUI, the SSH & Telnet ports are still ACTIVE and are not disabled. Found this info from performing a port scan on the GS728TPv2 switch.
RESULT:
PORT STATE SERVICE RESULT
22/tcp filtered ssh very bad
23/tcp filtered telnet very bad
443/tcp open https ok
So it appears the "filtered" ports can be opened via a magic packet. These ports should have been "closed"! If this is Netgear's way of implementing CALEA compliance. .. no wonder soooo many systems are being compromised by bad actors.
2. Still CANNOT harden SSH using Access Control. The SSH service is still missing from the list!!! Telnet should be provided for ACLing as well
Conclusion: Netgear does not provide business class secure firmware. The security in FW v6.10.10 is very suspect. This switch will remain out of service as we have been using a much better and secure brand now in our production environment.
Q: Did the Netgear responder even TEST your solution?... as most of it has found to be Vapor-ware and incorrect.
1. If Telnet & SSH are disabled in the WebGUI, the SSH & Telnet ports are still ACTIVE and are not disabled. Found this info from performing a port scan on the GS728TPv2 switch.
RESULT:
PORT STATE SERVICE RESULT
22/tcp filtered ssh very bad
23/tcp filtered telnet very bad
443/tcp open https ok
So it appears the "filtered" ports can be opened via a magic packet. These ports should have been "closed"! If this is Netgear's way of implementing CALEA compliance. .. no wonder soooo many systems are being compromised by bad actors.
2. Still CANNOT harden SSH using Access Control. The SSH service is still missing from the list!!! Telnet should be provided for ACLing as well
Conclusion: Netgear does not provide business class secure firmware. The security in FW v6.10.10 is very suspect. This switch will remain out of service as we have been using a much better and secure brand now in our production environment.
Q: Did the Netgear responder even TEST your solution?... as most of it has found to be Vapor-ware and incorrect.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!