NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
ecomike
Jan 27, 2022Follower
Vulnerable to NetUSB hack? AC2600 R7450
SentinelOne published a report detailing a NetUSB vulnerability in Kcode's firmware software that allows hackers to take over a router from the WAN via port 20005.
https://www.sentinelone.com/labs/cve-2021-45608-netusb-rce-flaw-in-millions-of-end-user-routers/
Will NETGEAR be releasing update firmware to fix this bug?
How can I close port 20005? (and please don't reply that it is essential for proper functioning... this port should never have been available over the Internet, and it has a stack overflow that opens the router to complete takeover.)
2 Replies
Sort By
So have to tested this on your router?
How do you know if yours is effected?
- HomeUserIAAspirant
Test with GRC | ShieldsUP! — Single Port Probe from within your network.
R8500 firmware 1.0.2.156 (from December 2021) predates this vulnerability, and unfortunately seems to cause DHCP to sporadically fail - creating problems with pretty much every web site.
Echoing the query to netgear - is there an updating about to be released?