NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
pkellum
Jan 09, 2026Aspirant
Why is my Netgear router trying to hack my NAS?
I had this happen with another Netgear router and returned it and got another, but same thing. The router is constantly trying to log into my Synology NAS using usernames like "user" and "admin". I...
- Jan 11, 2026
schumaku wrote:
Intrusion detection is active for any service active on the Syno (or QNAP, or Asustor, ...) offering or requiring authentication. In this post is -must- be active, despite the OP claims SSH insists only enabled on devices requiring it - however, SSH access attempts are logged.
I was wondering if perhaps sftp or an rsync-over-ssh backup job is configured???
schumaku wrote:
Remains the curiosity, how are there ssh packets reaching the NAS (behind of the NAT router on the LAN), and on which port
I think Armor's device scan is sending the packets and looking for vulnerabilities. So in fact they are coming from the router. But It's not a service I use, so I have no way to confirm.
pkellum
Jan 10, 2026Aspirant
The usernames it is using to try and get into my NAS with are ones like "vagrant", "root", "mysql", and "andy" (for some weird reason...). The online chat person says it is my NAS blocking the router, which it should, and that I should unblock all those usernames so the router can use them. And then they disconnected the chat.
StephenB
Jan 10, 2026Guru - Experienced User
pkellum wrote:
"The IP address [192.168.1.1] experienced 10 failed attempts when attempting to log in to SSH running on Synology418play within 5 minutes and was blocked..."The usernames it is using to try and get into my NAS with are ones like "vagrant", "root", "mysql", and "andy"
What model router are you using, and what firmware is it running?
Are you seeing any attempts to log into other devices on your network?
Is Armor enabled on the router?
- pkellumJan 10, 2026Aspirant
Nighthawk Tri-Band WiFi 7 model RS280S. Firmware: 1.0.5.22. I have SSH disabled on most of my other devices except a couple game servers and I see the same attempts on those. Everything is defaults and it looks like Armor was enabled when I set up the router.
- schumakuJan 11, 2026Guru - Experienced User
pkellum wrote:
I have SSH disabled on most of my other devices except a couple game servers and I see the same attempts on those.
The first step in establishing an SSH (or SCP) session would be opening up a TCP connection. Which can't - unless some kind of SSH service listener is enabled on your NAS, waiting for a connection, including the possible vulnerability checking.
Test with something like this to check if there is some listener on port 22 active on your NAS:
netstat -an | grep 22- StephenBJan 11, 2026Guru - Experienced User
schumaku wrote:
unless some kind of SSH service listener is enabled on your NAS, waiting for a connection,
pkellum​: Synology NAS do have intrusion detection, and I think it is being triggered by Armor's device scan. See this post (from 2022):
So begin by disabling Armor, and see if the problem stops.
schumaku​: Note per this post, the intrusion detection on the Synology is enabled even if ssh is not enabled.