NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
cetheridge30
Dec 11, 2016Star
The last straw: new vulnerability for R7000 R6400 R8000
Well, this is pretty much the last straw for me. I knew it was only a matter of time considering all of the broken promises, the messages of "coming soon", and flat out abondonment of your products N...
- Dec 14, 2016
Hi All,
The Security Advisory for VU 582384 has been updated.
Also, for more information see the link below.
SoCal
Dec 13, 2016Aspirant
Well...I'm in and not out.
NETGEAR:
- Publicly acknowledged the issue.
- Made the issue mission critical.
- Provided a beta during the interim.
I'd say that's pretty darn good on NETGEAR's part!
Also, I am now contemplating the purchase of a R9000 or an Orbi setup as my R7000 has been stellar on all fronts. Yep, I'm in all the way. Happy Holidays to all!
cetheridge30
Dec 13, 2016Star
The problem is that Netgear has NOT acted responsibly in this matter. As others have stated, they sat on this vulnerability, and only when the details got released to the public did they decide to act on it. I'm not trying to imply that it is this easy, but they really only need to comment out the line in the code that responds to these HTTP requests. The real issue in my mind is that A) they reacted instead of being proactive. This is not a good trend from a company that sells products that are supposed to protect their customers networks. B) I would almost put money on the fact that we only get a patch/firmware that just fixes the most current problem. What about Article ID: 30632, the "Web GUI Password Recovery and Exposure Security Vulnerability" (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/R8000-Firmware/m-p/1130926#M37981)??? Will this fix be included as well? They said they are going to fix it. Also, in other messages on this forum, a mod had said that they were working on an updated implementation of OpenVPN (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/When-R8000-firmware-with-IOS-support-for-OpenVPN/m-p/1046301#M26696) Will that be included as well?
I'm still out.
- cetheridge30Dec 13, 2016Star
One additional note: I still support an ASUS RT-66U and a 68U for my parents and extended family. I bought into the R8000 because of the need to cover a lot of area without extenders and bought into its "performance", however. The 66U is over 3 years old and it STILL gets regular updates every few months with its latest update being from October.
- ElaineMDec 14, 2016NETGEAR Employee Retired
Hi All,
The Security Advisory for VU 582384 has been updated.
Also, for more information see the link below.