NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Usr184
Apr 11, 2020Guide
ISP will not update customer owned equipment
My ISP is Mediacom Cable. My cable modem is a Netgear CM600 running on an ancient firmware. My ISP will not update the firmware because I own the equipment. Netgear says they make the updated firm...
FURRYe38
Jun 21, 2022Guru - Experienced User
Be cause it's a DOCSIS spec requirement that ISPs update modems. Not NGs requirement.
ISP are apart of the company/customer/ISP relationship.
All modem mfrs develop the modem FW, Then modem mfrs send this to the ISPs. ISPs are responsible to test any new FW versions coming from modem mfrs to ensure it works and works on there ISP network system prior to pushing to user modems.
Been like this for years.
blitz120 wrote:
What I don't understand is why Netgear does not support their paying customers (those who purchase the equipment) updating their own modem's firmware. I understand that the ISPs like to do so, but they are not a part of the company/customer relationship. This also allow the ISP to introduce modified versions of the software, which could reduce the customer's security.
I would really like to see Netgear directly address this (not "we don't do it", but why they refuse to favor their customers over third party services.
blitz120
Jun 21, 2022Aspirant
If it is part of the DOCSIS 3.1 spec (and that it specifies that firmware MUST NOT be updatable by the end user), then Netgear should explicitly state that on their download page(s), preferably with a reference to the particular DOCSIS document and section number.
I just perused several of the DOCSIS 3.1 documents, centering around CM-SP-CM-OSSIv3.1-I22-220216: Cable Modem Operations Support System Interface Specification, and could find nothing that addressed this.
I would like to get such a reference.
Note that this approach has serious security risks, given that a malware-containing firmware version could be introduced either by the ISP or by a third party getting access to the cable network upstream of the cable modem. Since the end users cannot access the firmware to perform a clean install, they may rely only on the reported firmware version, without even the option of checking and verifying checksums for what is installed. One would think this would introduce a substantial risk for the ISP, since they would be totally liable for any such malware being introduced, without giving the end user any means of checking this themselves.
- FURRYe38Jun 21, 2022Guru - Experienced User
I believe one reason why ISPs are not responsible for FW updates on modems is due to a past history of FW being not fully tested or developed and tested well. ISP pushed bad FW to user owned modems thus bricking or causing modems to become bad. ISP then incurred costs to replace the user owned modems at the ISP cost and expense. I believe this was one reason why ISPs are now testing FW and making final certifications on cable modem FW BEFORE they push to any modem. Some ISPs will just not push FW to any user owned modems, only ISP owned or rented modems from the ISP.
There are ways to that users CAN see and view FW versions on modems. Thats always been around. Just can't update them.
Again, been like this for years. NG isn't the only one. ALL other cable modem Mfrs follow same policy and spec.
Enjoy.