NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

SteveD_DC's avatar
Jun 02, 2024

RBK653 Firmware Woes

Firmware not there: RBK653 = RBR750 + 2x RBR350

 

I purchased the Netgear RBK653 kit (Router + two satellites) a year and a half ago. Two months ago, Netgear released a firmware update for the router — but not the satellites:

I’ve learned (the hard way!) that one should never update the router unless (1) you’ve updated the satellites first, and (2) the target firmware versions (satellite and router) are a match.

 

Since the v7.3.x.y firmware update, according to the release notes, “addresses security vulnerabilities,” that means that anyone with an RBK653 kit has been operating for almost two months with an under-patched router — and is therefore vulnerable — because Netgear has not provided a patch for a fairly recent device (which I think is irresponsible of them). 

 

Other than buying additional Netgear hardware (which I would not want to do right now), is there any alternative — or way to goose Netgear into actually supporting their recent products?

 

And recommendations would be welcome.

9 Replies

Replies have been turned off for this discussion
    • SteveD_DC's avatar
      SteveD_DC
      Guide

      Hi, schumaku, thank you for trying to help.

       

      The links you provided are for the firmware versions currently installed — and were released in December 2022 (a long time ago).  The current firmware for the RBR750 is 7.2.6.31 (released on April 10), which would be what I would like to use if Netgear had provided that update for the RBS350’s that came with my RBR750. Without the corresponding 7.2.6.31 for the satellites, the 7.2.6.31 update for the router should not be used. That is precisely what you posted — and precisely the problem I am asking about.

       

      I wish it was that easy, but clearly it is not.

  • Just disable Auto update on your RBR. V7 FW is not compatible with RBS350 series units. Not sure if NG will be updating them or not. If the system works with v4 version loaded on all units, you'll need to keep v4 version on all units. You can't update the RBR to v7 or the RBS350s will no longer work.

     

    Maybe later at some point if NG doesn't do anything for the 350s, find you some used 750 RBS on places like Amazon, Ebay or Shopgoodwill. Get one or two 750s then update them to v7 FW first the the RBR lastly.

     

    If your having problems with your system, please post the details and we can help you trouble shoot them. 

     

    Good Luck


    SteveD_DC wrote:

    Firmware not there: RBK653 = RBR750 + 2x RBR350

     

    I purchased the Netgear RBK653 kit (Router + two satellites) a year and a half ago. Two months ago, Netgear released a firmware update for the router — but not the satellites:

    I’ve learned (the hard way!) that one should never update the router unless (1) you’ve updated the satellites first, and (2) the target firmware versions (satellite and router) are a match.

     

    Since the v7.3.x.y firmware update, according to the release notes, “addresses security vulnerabilities,” that means that anyone with an RBK653 kit has been operating for almost two months with an under-patched router — and is therefore vulnerable — because Netgear has not provided a patch for a fairly recent device (which I think is irresponsible of them). 

     

    Other than buying additional Netgear hardware (which I would not want to do right now), is there any alternative — or way to goose Netgear into actually supporting their recent products?

     

    And recommendations would be welcome.


     

    • SteveD_DC's avatar
      SteveD_DC
      Guide

      FURRYe38, having no problems with the system. But running out-of-date firmware on a router, especially when vulnerabilities have been identified and patched, represents a security risk. Once a firmware update is released, it is frighteningly easy for the bug(s) it fixes to be reverse engineered and exploits developed.

       

      So, I am deeply troubled that it has taken this long for Netgear to get around to updating the other satellites that pair with the RBR750s. It is damn irresponsible of them. It would be one thing if the RBS350’s were five years past the point where they were being sold (and therefore end-of-life). And for there to be no indication of when the update would be available (if ever) makes me really question the wisdom of my spending hundreds of dollars on this kit less than two years ago. I’ve been a fan of Netgear for a long time, but it seems as if they don’t really care about existing customers as long as they can sell new, shiny toys to new ones.

       

      Thank you for posting. If you have any sway with Netgear (you are clearly a prolific contributor to the forums, so maybe they will listen to you), please give them a poke for me.

       

      • FURRYe38's avatar
        FURRYe38
        Guru

        What are these vulnerabilities that you refer too? 

        Links please. 

         

        Something to check with as well:

        If you are a NETGEAR customer with a security-related support concern, you can contact NETGEAR customer support at techsupport.security@netgear.com
        For all other issues, visit http://www.netgear.com/about/security/

        To report a security vulnerability, visit https://bugcrowd.com/netgear

         

        It's up to NG to deploy fixes for issues they find or brought to them. 

        Also up to NG to set EoL policy and such. The AC series is EoL as well as some AX series I see:

        https://www.netgear.com/about/eos