NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
cetheridge30
Dec 11, 2016Star
The last straw: new vulnerability for R7000 R6400 R8000
Well, this is pretty much the last straw for me. I knew it was only a matter of time considering all of the broken promises, the messages of "coming soon", and flat out abondonment of your products Netgear.
There is a new vulnerability out (shocking right?) that is affecting multiple routers and the way Netgear has handled the R8000 gives me less than zero confidence that they will keep their word, or do anything with this product anymore. In this landscape, everything is being attacked on a regular basis and Netgear has only proven that they will not keep up with the fast pace of security.
I'm out.
Hi All,
The Security Advisory for VU 582384 has been updated.
Also, for more information see the link below.
28 Replies
Replies have been turned off for this discussion
- SoCalAspirant
Well...I'm in and not out.
NETGEAR:
- Publicly acknowledged the issue.
- Made the issue mission critical.
- Provided a beta during the interim.
I'd say that's pretty darn good on NETGEAR's part!
Also, I am now contemplating the purchase of a R9000 or an Orbi setup as my R7000 has been stellar on all fronts. Yep, I'm in all the way. Happy Holidays to all!
The problem is that Netgear has NOT acted responsibly in this matter. As others have stated, they sat on this vulnerability, and only when the details got released to the public did they decide to act on it. I'm not trying to imply that it is this easy, but they really only need to comment out the line in the code that responds to these HTTP requests. The real issue in my mind is that A) they reacted instead of being proactive. This is not a good trend from a company that sells products that are supposed to protect their customers networks. B) I would almost put money on the fact that we only get a patch/firmware that just fixes the most current problem. What about Article ID: 30632, the "Web GUI Password Recovery and Exposure Security Vulnerability" (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/R8000-Firmware/m-p/1130926#M37981)??? Will this fix be included as well? They said they are going to fix it. Also, in other messages on this forum, a mod had said that they were working on an updated implementation of OpenVPN (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/When-R8000-firmware-with-IOS-support-for-OpenVPN/m-p/1046301#M26696) Will that be included as well?
I'm still out.
One additional note: I still support an ASUS RT-66U and a 68U for my parents and extended family. I bought into the R8000 because of the need to cover a lot of area without extenders and bought into its "performance", however. The 66U is over 3 years old and it STILL gets regular updates every few months with its latest update being from October.
- BoDEANApprentice
"Acew0rm alerted Netgear to the problem on Aug. 25, but never heard back, the researcher told Fortune in a direct message on Twitter. So four months later, Acew0rm took the find public"
Made the issue "mission critical?"
If that was the case, we would have had a new FW in August/September....
- I like the way you think. I have really looked at pfsense as well. A little embarrassed to say that I am a network admin by trade and rely on plastic boxes for my home network. I mean there is something to say for ease of use but I may just have to bite the bullet and go all in on a custom box.
- CaptivaTutorYour done here so no one can see your posts. What did you type?
For someone who wants the thread locked, you sure do post a lot.
- mdgm-ntgrNETGEAR Employee Retired
If you think a thread should be locked then you should PM a NETGEAR mod and the mod can consider the request.
Please stick to the topic.
- I'm "out" as in, I will no longer be purchasing Netgear products. If an admin deems that this communication is not within the guidelines of their community then they can exercise the right to lock it. Wow. Thought this community would be a lot more understanding as we are all in the same boat with the lack of support. Guess there's some bad apples in every bunch.
cetheridge30 wrote:
I'm "out" as in, I will no longer be purchasing Netgear products. If an admin deems that this communication is not within the guidelines of their community then they can exercise the right to lock it. Wow. Thought this community would be a lot more understanding as we are all in the same boat with the lack of support. Guess there's some bad apples in every bunch.I am glad you voiced your opinion. Really thinking seriously about ditching home routers for a pfsense box with a separate AP within the network. I guess that makes me pariah here also.
- CaptivaTutor
I'm the bad apple? I've been in online communties since before usenet in the mid 1980's. What I don't understand is someone announing to the community is that they are done, but keep coming back for more. You are done with Netgear. We get it. Move on. Others here need solutions and are not in a position to quit yet.
If the shoe fits...
I don't think your community experience is in anyway relevant. Either way, my hope is that others will see this post and actually have constructive conversation about the situation. Yes I'm done with Netgear meaning I will never buy one of their products, but I still have this 250 dollar piece of junk and I'm trying to figure out what to do with it. Being done also doesn't mean that I don't care about others in the community, finding more issues/solitions, or even hearing from a Netgear rep would be nice. Your original comment is not constructive or helpful in any way regardless of your experience.
- CaptivaTutorI thought you were "out" so can this thread be locked please?
Captiva wrote:
I thought you were "out" so can this thread be locked please?You are mindguarding the group against dissent here. That's a symptom of groupthink. Someone has voiced displeasure and said they are "out" so their opinion no longer counts even if they still own the product? People reading this need to know how customers feel about this issue.
Another symptom of groupthink is illusion of invulnerability. How long has Netgear known of this issue? I've read Acew0rm notified them in August. If so that's quite the response lag. And apparently the canard about keeping remote management turned off isn't quite the panacea it seemed before this vulnerability hit.
Maybe Netgear needs to buckle down and get less reactive and more proactive.
- mdgm-ntgrNETGEAR Employee Retired
As our investigation continues we will provide further updates to our security advisory. Thank you for your patience.
- antProdigy
What about R6300 v1?
- Did you actually read anything I posted? They promised features coming to the R8000 that lower models already have. They have been saying, coming soon for over a year. There are open vulnerabilities they have yet to patch, and to quote myself, they have done nothing to bolster my confidence that they will patch it in a timely manner, hence the point of my whole post.
- It's not about finding something less buggy. ALL code has bugs. It's about purchasing something from a company that is active in securing their product when vulnerabilities are discovered. Netgear has done nothing to bolster my confidence that they are willing to keep their products up to date. I would rather have a product with bugs and a company willing and actively fixing them than a company that hasn't released an update in 6 months.
- BoDEANApprentice
A Men brother. Netgear seems to be EXTREMELY SLOW with releasing FW updates and addressing things. Instead of pushing out new routers every month, lets fix/secure what you already have on the market!
What makes you think Netgear is not going to fix a bug as big as this one?
TheEther wrote:What makes you think Netgear is not going to fix a bug as big as this one?
What's the timeline of their knowledge of this bug? Sources say since August. So they got on the ball when it became a matter of CYA instead of prudence or morality? I guess we can offset the stances of fiduciary responsibility versus externalities, especially those of potential victims of botnets. But shareholders ALWAYS win over stakeholders and society in general. That's bottom line.