NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Morganino
Jun 26, 2017Tutor
Netgear R7000 and OpenVPN for Android App
Hi, since last OpenVPN for Android App update (v.0.6.73) downloadable at the following link: https://play.google.com/store/apps/details?id=de.blinkt.openvpn OpenSSL version was upgraded to 1.1 and...
- Feb 28, 2018
Thanks everyone for feedback so far. Attached is version 1.0.1. I fixed some typos, added a suggestion to clean up your tftp folder when you're done, and made a note about the OpenVPN version that's most compatible with the document.
Some users looking to work through this doc may find that they can avoid Step 1 by visiting this hidden page:
If the debug page loads and there is an "Enable Telnet" option then you got lucky. Note that either the debug page or the option to "Enable Telnet" may not exist on your device or firmware version. Remember to check that this option is disabled after you're finished because having telnet enabled is a security risk.
Diggie3
Dec 28, 2017Luminary
Netgear is using MD5 for the VPN?!
HOLY ****! That's terrible!
Not only this, but we can't even generate new keys on the router still.
Netgear security is a total joke if this is true.
HOLY ****! That's terrible!
Not only this, but we can't even generate new keys on the router still.
Netgear security is a total joke if this is true.
96708
Dec 28, 2017Apprentice
NG doesn't give a flying F how many times you call or write about MD5 here. So throw the hammer down and file the BBB complaint.
- CyBuzzDec 29, 2017Guide
BBB Complaint filed.
- 96708Dec 29, 2017Apprentice
Good for you. I filed one as well. Keep the pressure on. I consider this a simple napalm flyover spayobver on them to light them on fire so to speak. The sum all fears nuclear option is still available and that would be initiating the help of cybersecurity firms. Only with broad exposure in the news -- and damage to the image of the brand along with lost sales -- will they really do anything IMO.- Diggie3Dec 31, 2017LuminaryAfter spending a day or so, I have managed to replace the VPN certificates and keys on the R7000 and verified it's working using OpenVPN Client app for Android. Also verified the old, replaced keys are dead.
I can try to post a tutorial but it will take some time and will be quite long just because of the number of tools involved. I also can only post a Windows guide but it should be possible from any platform.
Anyway: My point is it's possible, but it definitely isn't easy.