NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Johnny54321's avatar
Johnny54321
Aspirant
Feb 10, 2018
Solved

R9000 WiFi On/Off button OPENS WiFi to the Public, HUGE Security Flaw!

Nighthawk X10 R9000 Router Firmware Version V1.0.3.6

WiFi is configured to use WPA2 Security.

Pushing the WiFi On/Off button for 3 seconds turns of the Button LED, and the Antenna LED's, and Shows WiFi OFF in the RouterConfig

WiFi Button OFF Shows WiFi Turned OFF

!!!HOWEVER!!! The Router still broadcasts with WiFi turned off, it just broadcasts without the Security Key and is OPEN TO THE PUBLIC.

My network is exposed, and I would like to turn the router on only when it is needed to reduce WiFi radio exposure to myself sitting right next to the router, and to my kids who sleep directly above it.

The Moment I realized the WiFi Off Button just removes security and opens my home network to the Public!

WiFi Button off, Devices connected and Bandwidth activity showing

WiFi Button off, Devices connected and Bandwidth activity showing

My Thoughts:

This seems like a firmware issue, unfortunately, my 3month support with NetGear has expired a few weeks ago, and I can't submit a ticket without paying $50 for their service.

I am still under warranty, and perhaps sending the router back, and going back to my old router will work, but then I'll just have to reconfigure my network to function without it, and then I wont need it.

7 Replies

  • FURRYe38's avatar
    FURRYe38
    Guru - Experienced User

    Someting to get ahold of one of the Forum moderators about and ask them for help and info regarding this. 

     

    I presume your FW is up to date? Make sure it is. 

     

    You might try Voxels R9000 FW. It uses same UI, however back end stuff is better managed. 

    https://www.voxel-firmware.com/Downloads/Voxel/html/r9000.html

     

    Might give this a try, if same thing still happens then the core NG code would need to be looked at by NG. 

  • Hi Johnny54321,

     

    Let me check on this and will get back to you.

    • schumaku's avatar
      schumaku
      Guru - Experienced User

      JamesGLwrote:

      ,Let me check on this and will get back to you.


      James, there had ben a few similar reports on this issue before. On my R9000 running 1.0.3.10 (and intermediate builds after .6) I have not seen this (random) behaviour anymore.

       

      However, there is a new issue: With WPS disabled (with the WPS button LED off) using the WiFi button to switch off all wireless networks - when switching the wireless networks on again, the WPS button is lit (with SmartConnect enabled). Reported to Tw before the new Chinese new year.

      • JamesGL's avatar
        JamesGL
        Master

        Hi schumaku,

         

        WPS cannot be disabled unless the security is set to WEP. WPS LED will lit off if wireless is disabled on the router and once you have enabled it WPS LED will lit up again.

    • Johnny54321's avatar
      Johnny54321
      Aspirant

      That update solved it!

      Now, it all works just fine.

       

      To recap, I have WPA2 Security on my WiFi Broadcast, and now, when I push the WiFi button on the router, it turns the WiFi On/Off, where as with the previous update, pressing the button would turn On/Off the WPA2 Security and be wide open to the Public.

       

      Thank You!

    • JamesGL's avatar
      JamesGL
      Master

      Hi Johnny54321,

       

      I am glad to know it works. :)