NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

fli's avatar
fli
Follower
Aug 06, 2021

firmware vunnerability

It's unbelievable that the firmware is so vulnerable:

1. admin web login with clear text password without TLS or SSL

2. The CVE-2018-10822 issue

3. No way to stop SSID broadcasting

 

With this price tag, could you enhence the above?

5 Replies


  • fli wrote:

    It's unbelievable that the firmware is so vulnerable:

    1. admin web login with clear text password without TLS or SSL < Most routers don't need any TLS or SSL on the admin log in from a local side. Been like this for a long time now. 

    2. The CVE-2018-10822 issue< This issue is in regards to D-Link effected routers. Not NG. 

    3. No way to stop SSID broadcasting< Been like this since Orbi AX released. 

     

    With this price tag, could you enhence the above?


     

  • I could find a non-broadcasted SSID in about 30 seconds on my cell.  That is not security.

    • FURRYe38's avatar
      FURRYe38
      Guru

      You have a screen capture of this? 


      Ragar99 wrote:

      I could find a non-broadcasted SSID in about 30 seconds on my cell.  That is not security.


       

      • Ragar99's avatar
        Ragar99
        Luminary

        I think you misunderstood.  I am not saying Obri allows the user to hide the SSID.  I meant in general it is pretty easy to find hidden or unbroadcasted SSIDs.