NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

aabbcc's avatar
aabbcc
Aspirant
Apr 24, 2018

Easy to get the router's account and password

It's easy to get the router's admin's account and password through the Nighthawk app.

When my phone is connected to a netgear router,I only need to open the Nighthawk app and choose login in with touchId(use fingerprint,without the router's admin account and password),then I get the router's authority even the root's account and password is plaintext and can be inquiried from the app.It's dangerous and horrible.Hope that the bug can be fixed soon.

9 Replies

  • michaelkenward's avatar
    michaelkenward
    Guru - Experienced User

    aabbcc wrote:

    It's easy to get the router's admin's account and password through the Nighthawk app.

     


    Can you explain what password you are talking about here?

     

    Is it the one you use to get in to control the device or the one you need to use the wifi?

     

    And what Nighthawk App is this? Android? iThing?

     

    I don't use fingerprint detection, but wouldn't you expect it to respond to your fingerprint to get in to the thing?

     

    Or are you saying that it will respond to any fingerprint?

     

    Or does it let you in even if you haven't set up fingerprint recognition?

     

    The big risk is if anyone can just pick up your device and get into the router. Is that what you are saying?

     

    • aabbcc's avatar
      aabbcc
      Aspirant

      michaelkenward wrote:

      aabbcc wrote:

      It's easy to get the router's admin's account and password through the Nighthawk app.

       


      Can you explain what password you are talking about here?

       

      Is it the one you use to get in to control the device or the one you need to use the wifi?

       

      And what Nighthawk App is this? Android? iThing?

       

      I don't use fingerprint detection, but wouldn't you expect it to respond to your fingerprint to get in to the thing?

       

      Or are you saying that it will respond to any fingerprint?

       

      Or does it let you in even if you haven't set up fingerprint recognition?

       

      The big risk is if anyone can just pick up your device and get into the router. Is that what you are saying?

       



      I'm talking about the password of the control of the router,IOS app.

      Firstly,connect the netgear router by wifi.

      Then,open the Nighthawk App.

      Choose "LOG IN WITH TOUCHID"

      Success,and get the control of the device.Even can get the admin's password.

       

      It means anyone once he connect the netgear router's wifi I shared and install the nightkaws app,He can get the control of the device by his own TOUCHID through the nightkaws app without admin's account and password and can do anything he wants to do. 

      • schumaku's avatar
        schumaku
        Guru - Experienced User

        When activating the Touch ID (fingerprint sensor) in the App, you allow the App to store the admin password - thus when unlocking the App using the Touch ID, you allow the App to access the router and offer all the App convenience to the customer.

         

        This usage and security model is the very similar in many applications, even finance Apps like Paypal allow almost full access to your Paypal accounts.

         

        One might dispute that the Nightawk App does not allow removing the Touch ID access however, reverting to password is apparently to difficult for many home users or consumers, as this is one of the most asked questions: "I forgot the router password.". That's why the capability is there in the App - to see the password - after a valid authentication by Touch ID.