NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

warpdag's avatar
warpdag
Apprentice
Jan 25, 2020

RBR850 Massive Security Fail - Many ports responding to requests

Just bought the thing, using the latest firmware V3.2.9.2_1.2.4. Did not Disable Port Scan and DoS Protection.

 

WAN ports respond to unsollicited requests, instead of ignoring. They do respond closed, but still, the safe behavior should be no response at all, i.e. stealth. Try for yourself: https://www.grc.com/x/ne.dll?bh0bkyd2

 

This is really basic security stuff... just saying.

31 Replies

Replies have been turned off for this discussion
  • Thanks for letting us know. I and others have already seen this and reported it to NG. No responce as of yet. Hopefully someone will check in to this. 

    • warpdag's avatar
      warpdag
      Apprentice

      Added a screenshot just in case. Firmware is obviously far from being ready for prime time.

  • Yes, I think were done. FW has been updated and seems it was finally fixed. Thank you NG. 

     

    I recommend users update there FW if there concerned about Orbi security. 

     

    Good Luck and enjoy. 

    • dglsmcd_USMC's avatar
      dglsmcd_USMC
      Luminary

      Using Shields Up from the grc website with the current firmware available (not available for manual download) I received a "passed" having achieved true stealth analysis for all service ports. We are indeed done with this thread.

      • FURRYe38's avatar
        FURRYe38
        Guru

        Thanks for letting know what you see as well. 

         

        Enjoy.