NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
mikejvir
Mar 01, 2020Aspirant
R7000 (AC1900) Readyshare and Windows 10
Hello, I purchased the Netgear AC1900 router in 2016 because I needed 802.11ac WiFi for a new laptop (windows 8). I hooked a USB hard drive (2TB) to the router for storing common files (mostly m...
mikejvir
Mar 01, 2020Aspirant
Thanks, but that is not the issue. The USB drive works with the router, Windows 7 and Window 8 can read and write with no issues. IT is the new laptop which has Windows 10 that can not access the USB drive.
michaelkenward
Mar 02, 2020Guru - Experienced User
- mikejvirMar 02, 2020Aspirant
Hello Michael,
Well this seems like it will work (I am not at home), but it is from 2017 and Netgear has not fixed the issue as of the last software update (Firmware Version 1.0.9.88 Aug 2019). Given that this is over 2 years old, it look like they never will.
As someone who will not get into the depth of networking, it looks like I need to find a router that does not use SMBv1.
Thanks for the link.
Mike
- schumakuMar 02, 2020Guru - Experienced User
mikejvir wrote:As someone who will not get into the depth of networking, it looks like I need to find a router that does not use SMBv1.
The SMBv1 warning was almost obsolete when that referenced post was published. The ransomware issues allowing the non-authenticated access regardless of the config was fixed. There was (and is) even more false hype in the net than on SARS-CoV-2.
Then, a client capable of using higher SMB protocol levels does automatically negotiate to thre highest version available on the client and the server. This is not the reason for disabling SMB 1.0 on the routers supporting higher protocol versions.
Reality check: How many ReadyShare routers and NAS using SAMBA and have configured shared folders with anonymous/guest access not requiring usename and password protection? Using the latest and greatest SMBv3.x won't protect you here....
Conclude: Very bad idea to warm up known faux information here.
There is no need to throw away a router with an updated SAMBA installation against these ransomware vulbnerabilities!!!
- michaelkenwardMar 02, 2020Guru - Experienced User
mikejvir wrote:
Well this seems like it will work (I am not at home), but it is from 2017 and Netgear has not fixed the issue as of the last software update (Firmware Version 1.0.9.88 Aug 2019).
I linked back to a post from 2017 because it explains what to do. Not much has changed since then on the "fix" you can apply.
Why should Netgear do a firmware update?
Do you have any evidence that this is a serious security issue?
Some people might complain that it is a Microsoft problem.
- schumakuMar 02, 2020Guru - Experienced UserThe vulnerability was indeed an issue which hit both Microsoft and the SAMBA implementation. Netgear has addressed the issue on most newer routers within more or less reasonable time.
People seem to expect that Netgear would add SMB 2.0/2.1 and SMB 3.0 at least. Most of these users don't understand that the bigger problem for many is the absence of the NetBIOS discovery and name resolution - what does require the installation of the SMB 1.0/CIFS Client feature on Windows 10. SMB 2.x would add much better performance over the Internet (read: over VPN), SMB 3.0 introduced Jumbo Frame support (Netgear consumer router customers are still left back dreaming of JF on the LAN), and offers some optional encryption (hitting the performance again). SMB 1.0 is in its current implementation reasonable secure for using in a consumer home or SOHO environment. Yes, some router models got the higher SMB protocol implementation. The effective missing part is WSD - odd as Netgear developer has implemented a very small footprint version for embedded systems.