NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
I just bought the Netgear R7000. While configuring it, obviously the default user name was admin and it had a default password.
Went in and changed the PW but could not find anywhere to change the initial login name from Admin to something more secure so I reached out to support. I was told ADMIN is hard coded into the firmware and cannot be changed. I still can't believe this is true. If it is, someone needs to explain the justification to remove fully 1/2 of the security layer!
I can't wait to tell the Devops guys at work about this blunder!
Tech support, please tell me the support I was given is incorrect.
2 Comments
- michaelkenwardGuru - Experienced User
al06360 wrote:
I was told ADMIN is hard coded into the firmware and cannot be changed. I still can't believe this is true. If it is, someone needs to explain the justification to remove fully 1/2 of the security layer!
I can't wait to tell the Devops guys at work about this blunder!
Tech support, please tell me the support I was given is incorrect.
This has been, and probably always will be, the case. It is something that most router makers do. Even the much lauded Asus does the same thing. (Amaze yourself by checking a few different makes.)
A bit of research into network security will show that the chances of alien invasion are minimal when dealing with something like this on your local network. I assume that you have decent passwords for the router and for Anywhere Access., if you use that.
You might like to think twice before talking to "the Devops guys". They may wonder what the hell you are talking about.
As to "Tech support", you should know that this community is essentially a user-to-user venue with some input from a small band of Netgear techies.
Most of the answers come from fellow users who have no connection with Netgear. They just have a lot of collective experience and are familiar with the sort of problems that turn up here.
- al06360Follower
Looks like my reply didn't post.
The ASUS router I just replaced had the ability to change the default login name. To not be able to fully removes 1/2 of the security layer. Perhaps there's an MFA option to use?
The Devops team where I work create security software for the US government. I won't go into detail but it protects you and I from the rest of the world.
I really appreciate all the people paid or unpaid who participate in any forum to answer questions, but a flaw is a flaw.