NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
brianld
Oct 19, 2023Apprentice
Unrestricted access to router admin UI
This is an odd one that I can't seem to pinpoint: 1. Reset entire system to factory defaults. 2. Set up the system again. 3. Establish admin password, as required. 4. Login to Router Admin pag...
FURRYe38
Oct 20, 2023Guru
Just because one user sees a problem doesn't mean others should see same thing. Possible this users unit is just faulty or in a bad state. I've not seen this ever since day one on mine. I get the log in windows each and every time I go to the routers web page.
brianld
Oct 20, 2023Apprentice
Straq FURRYe38 An update on this issue:
I started from scratch today. Completely reset router and satellites. Went through the entire setup of my Orbi using the iOS app.
The issue of being able to get into router admin pages from any device on network is no longer occurring. Phew!
I did find a different potential security issue however. I would be curious if someone else could try to replicate it ...
It appears that the router will allow any browsers from a single device to access the admin portal if a user has logged in via that IP, and has not logged out.
How to reproduce:
1. Clear cookies on all browsers.
2. Using the browser of your choice (I used Chrome), login to your router's admin pages.
3. Do not click "Logout" in upper right. Just close/exit the browser.
4. Using any other browser (Safari in my case) from the same computer, open your router admin page.
5. You should be in without being prompted for a password.
I've tested this with multiple browsers, as well as within a VM on my Mac that shares the Mac's IP. Once a user has logged in from an IP, and has not logged out, anyone can administer the router.
This isn't an issue for me in particular, as no one else uses my laptop, and I can just be sure to logout. However, imagine a scenario where a household used a shared computer. If the admin portal had been logged into from that computer, and the session was not logged out, any other user of that computer would be able to access it, so long as the IP doesn't change.
- FURRYe38Oct 20, 2023Guru
I can produce this on my Win 10 PC with MS Edge and Chrome but can't produce this on Win 11 PC with MS Edge or FireFox, they give me the log in each time. Cleared browser caches on both as well.