NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
pihrm
Feb 19, 2023Guide
On the brink of throwing away RBR750 system
The router's admin web page ALWAYS eventually goes unresponsive (timeout). Sometimes it's ~3 days after a reboot; other times it's ~10 days, give or take a few days. It's rare it stays alive fo...
pihrm
Feb 22, 2023Guide
A screenshot of a browser unable to connect to an unresponsive service would not be enlightening.
Other data points:
- the Orbi app is also unable to connect to the router when it’s in this state
- all satellites remain responsive; browsing their admin pages works fine
- neither DNS nor browser choice is the issue (testing w/ telnet to router IP address yields same results)
Plainly put, the router’s admin service (or stack) dies after N days. Hard power cycle resurrects functionality…until another N days.
CrimpOn
Feb 22, 2023Guru - Experienced User
pihrm wrote:
A screenshot of a browser unable to connect to an unresponsive service would not be enlightening.
Other data points:
- the Orbi app is also unable to connect to the router when it’s in this state
- all satellites remain responsive; browsing their admin pages works fine
- neither DNS nor browser choice is the issue (testing w/ telnet to router IP address yields same results)
You have managed to enable telnet on this router? The last I heard Netgear had removed telnet from all Orbi models.
Multiple browsers. Multiple computers. Both http (port 80) and https (port 443) and all the usual web pages:
http://<ip of orbi>/hidden_info.htm
All simply "time out" - no response at all.
That TP-Liink system looks like quite a deal. 6E, Parental Controls, for $289.99 Would probably want to spend some time on their user forum. We know all about the shortcomings of the products we have, and close to zero about other brands.
- pihrmFeb 22, 2023Guide
CrimpOn wrote:You have managed to enable telnet on this router? The last I heard Netgear had removed telnet from all Orbi models.
Multiple browsers. Multiple computers. Both http (port 80) and https (port 443) and all the usual web pages:
There are ports other than just 23. 😉 But you're right, I should have clarified (mostly port 80). However, this gave me an idea...
All nodes have latest firmware, V4.6.14.3. The satellites all report:
Server: lighttpd/1.4.58
Lo and behold: https://www.cvedetails.com/cve/CVE-2022-41556/
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Who knows if this is the smoking gun, but it's certainly suspicious.
How does one submit a Bug Report or Feature Request to Netgear, in order to get lighttpd upgraded to at least 1.4.67?
- FURRYe38Feb 22, 2023Guru - Experienced User
- pihrmFeb 22, 2023Guide
FURRYe38 wrote:https://community.netgear.com/t5/Idea-Exchange-For-Home/idb-p/idea-exchange-for-home
If that's the best they offer, so be it! 🙂 "Idea" submitted:
Will beg for upvotes!