NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Riley78's avatar
Riley78
Guide
Mar 15, 2018
Solved

R6900: Security Issue found by Avast

I updated my Avast free antivirus to the current build and ran the Wi-Fi inspector. I had ran it recently and it found no problems. But now it reads:

"Your router or Wi-Fi hotspot is vulnerable to network attacks!
We have found vulnerabilities in your router or Wi-Fi hotspot that can be used by attackers to hack into your network.

Description
Our scan found a vulnerability on your router or Wi-Fi hotspot device. Your device contains a problem that can be misused by cybercriminals to break into your network and compromise your security and privacy.

Android devices used as a Wi-Fi hotspot can be also affected.

Solution
Some of the vulnerabilities may be patched in new versions of the device firmware or system update. Applying the latest firmware or system update may solve the issue.

Consult your device's manual for instructions. If an update adressing the vulnerability issue is not available, contact your devices's vendor or manufacturer to provide an update as soon as possible.

Details
We have identified the following problem with your router or Wi-Fi hotspot device:

DnsMasq heap buffer overflow vulnerability
Severity: High

Reference: CVE-2017-14491  http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14491

Google Security Blog: https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

Description:
The affected device's DNS service is running an outdated version of the DnsMasq software which is known to have a heap buffer overflow vulnerability.

Impact:
Any device connected to your network, including computers, phones, tablets, printers, security cameras, or any other networked device in your home or office network, may have an increased risk of compromise.

Recommendation:
The issue was fixed in DnsMasq software version 2.78, released in October 2017.

To solve the vulnerability on your device, apply the firmware or system update that contains DnsMasq software version 2.78 or higher provided by your device's manufacturer.

If an update addressing the vulnerability is not yet available for your device, you can secure your router or Wi-Fi hotspot with a strong password to minimize risks imposed by the vulnerability. We also advise you not to visit suspicious websites or run software from questionable sources".

 

I am running firmware version V1.0.1.44_10.0.28, and there is nothing newer.

 

I would appreciate any feedback on how to deal with this. 

 

  • So with the just released firmware version 1.0.2.4,  dnsmasq is finally updated to 2.78. 

    It only took one full year.

11 Replies