Orbi WiFi 7 RBE973
Reply

D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

andrewcuommo
Aspirant

D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

Dear all,

I have a strong suspect that my router has been hacked at Firmware level.

Here the happenings:

1) I suddenly lost access to wi-fi (all devices not able to connect with same error message "wrong password"). The network name didn't change (I set my own name, not using the netgear standard). Firmware was at latest version (don't remember the version though). Access control was on (I know it is not very useful) with no access for unknown devices. Password legth was 30+.

2) After factory resetting, I've set again the wi-fi.

 

NOTE: point 1 already happened some weeks back, I just repeated point 2 and set it back.

 

3) Netgear Genie (192.168.0.1) says firmware level is V1.0.1.48_1.0.1

4) When checking for firmware updates, Netgear assistant says "current version V1.0.1.44, New firmware version V1.0.1.48" ???

 

5) So the router is telling me something that doesn't match with Netgear assistant, that's not good. And it didn't happen previously, I've been able to update the firmware correctly and didn't get such conflicting message.

 

6) The assistant offers to download and install the new firmware. I did it 5-6 times, router seems to reboot but every time I am back to point 4. This really sounds to be wrong.

 

Did anyone had the same experience? Shall I consider D7000 as an easy hackable device? On top of the above the router offers from time to time to change the language to English (independently of the device accessing it).

Thanks to anyone, hope this post offers a good reference to you all.

Regards,

Andrew

Model: R7000|Nighthawk AC1900 Dual Band WiFi Router
Message 1 of 10

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

I have a problem understanding your message, especially the bit about firmware.

 


@andrewcuommo wrote:
3) Netgear Genie (192.168.0.1) says firmware level is V1.0.1.48_1.0.1

4) When checking for firmware updates, Netgear assistant says "current version V1.0.1.44, New firmware version V1.0.1.48" ???

  

 

What Netgear genie are we talking about here? This could be one of several things, the browser interface, a Windows or Mac application, or an Android iThing app.

 

And what is this Netgear assistant?

 

You can find the various firmware versions for your hardware here:

 

>>>> D7000 | Product | Support | NETGEAR <<<<

 

It is highly unlikely that someone has hacked your modem/router at a firmware level.

 

Did you reset the device to factory defaults after your firmware upgrade? If not, this could explain any odd behaviour.

 

New firmware sometimes introduces changes that are not compatible with the old configuration.

So a factory reset is the first thing to try if you have problems with new firmware.

Backup your configuration first and note down any important settings. (It would be nice if Netgear provided a way of saving those settings to a text file.) Netgear does not advise restoring old settings into new firmware, but if resetting does not fix your problem, and you have complicated settings, you might want to restore them.

 

 

Message 2 of 10
andrewcuommo
Aspirant

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

Dear Micael,

first of all thanks for your reply, appreciated. Please allow me to rephrase my statements and reply to your points:

- model is AC1900 wifi VDSL/ADSL Modem Router (model: D7000). This is what I see on the back of the device itself.

- I am not using any Netgenie app, I login using 192.168.0.1 (admin credentials) and use Netgear Genie from web interface (trying in parallel IE, FireFox and Safari)

- Where do I see current firmware level? from 192.168.0.1 (so Netgear Genie web) on top right I see "Firmware Version V1.0.1.48_1.0.1"

- Going into Advanced --> Adminstration --> Firmware Update --> Check, interface says

"Attempting to connect to Netgear Server 1. Please wait" followed by

"There is a new GUI text file available"

"Current Version V1.0.1.44" and "New Firmware Version V1.0.1.48" offering

"Do you want to download and use this new GUI text file?"

 

two comments here: 1) I see a conflict between versioning 2) whatever I do, the message appearing is always the same on next update check.

 

I did rest to factory twice (as I told you something similar happened twice) having the old Firmware appearing and then doing an upgrade again.

 

With regards to hacking risk: I originally thought that just somebody was kidding me hacking the wifi psw and changin it, but wifi and admin psw are different and quite long (not very long but still around 30chars), this would have been requiring quite some effort  and the area where I do live has few people, hence I thought something coming from internet. I think I need to setup a better logging to check if someone is really looking to drive e crazy 🙂

 

Hope it clarifies, please let me know your thoughts

Best regards,

Andrew

Message 3 of 10
Zuriel
Aspirant

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

I have D7000 and this router is hacked even after applying all recomended security advice disabling router pin etc, long passwords. updated firmwear to latest on Netgear site  resetting router, rechanging  all passwords inc router login.

Within seconds of connecting wifi I have 2 mobile phones appear on our network from outside accessing our wifi.

EVERYTIME wifi is connected. Can't disable SSID it says can't run wifi without it.

Have set up MAC address access only etc....

wifi passwords over 45 characters long.... using highest security available.

Contacted Netgear they said do all the usual  re-boot, reset. Done it all.

They wanted to charge me £50.00 extra money for six months, as out ouf their short 3 month warranty regarding free service help.

This is the worst supported products in UK.

Cant use 3rd party firmwear noone supports this D7000.

Beyong belief. Shoud have brought the Asus product like advised by shop.

THIS D7000 router is now an open door to anyperson who wan't to use our wifi. We can't turn it on at all.

Message 4 of 10

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language


@Zuriel wrote:

I have D7000 and this router

 

D7000 is not a router. It is a modem router.

 


@Zuriel wrote:
Within seconds of connecting wifi I have 2 mobile phones appear on our network from outside accessing our wifi.

EVERYTIME wifi is connected.

 

Where do you see these devices?

 

Seeing "phantom" phones is a well known "feature" of Windows. It often has nothing to do with Netgear. You can find other reports of this, and how to deal with it, by searching this forum.

 


@Zuriel wrote:
Can't disable SSID it says can't run wifi without it.

 


 

What does that mean?

 

You don't want to disable the SSID. You want to hide it. How you do this appears in the manual where it talks about Enable SSID Broadcast. The manual is here:

 

>>> D7000 | Product | Support | NETGEAR <<<

 


@Zuriel wrote:
They wanted to charge me £50.00 extra money for six months, as out ouf their short 3 month warranty regarding free service help.

 

This is a well known Ndetgear scam. Tell them to sling their hook and warn everyone you know that it is a ripoff. You'll get better support here.

 


@Zuriel wrote:
Cant use 3rd party firmwear noone supports this D7000.

 


 

Most third party firmware supports routers, not modem routers. Did you mean to buy a router?

 


@Zuriel wrote:
HIS D7000 router is now an open door to anyperson who wan't to use our wifi. We can't turn it on at all.

 


 

Not if you set up security, change the SSID and implement a password that only you know.

 

I suspect that most of your issues are easily dealt with by taking a cool approach and working through things a step at a time.

 

Message 5 of 10
Zuriel
Aspirant

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

If you read carefully what I have written you will see that I have followed all security settings advice given over the phone by NETGEAR and  the router/modem is STILL wide open for attack and access to our wifi.

What don't you understand about that?

You can't HIDE SSID it is not possible any more as this product has been HACKED.

How more plain can you describe the situation.

Our network when clicked on Network on windows 10 instantly reveals at least 1 mobile phone shows up - NOT a phantom phone or phones  CONNECTED to our network ONLY after the D7000 wifi in enabled!!!!

Our neighbour connects to our wifi without a problem with HIS phone!!

Speaks for itself really.

Nothing shows up untill WIFI IS ON!

That is not a windows problem it is a NETGEAR problem.

I know about the support or lack of support with 3rd party firmwear for other products ie ROUTER....

ALL security measures HAVE been correctly set up ok! 

STEP BY STEP.

Don't patronise.

This product is going back. A full refund is already  in process.

THANK you.

Message 6 of 10
netwrks
Master

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language


@Zuriel wrote:

If you read carefully what I have written you will see that I have followed all security settings advice given over the phone by NETGEAR and  the router/modem is STILL wide open for attack and access to our wifi.

What don't you understand about that?

You can't HIDE SSID it is not possible any more as this product has been HACKED.

How more plain can you describe the situation.

Our network when clicked on Network on windows 10 instantly reveals at least 1 mobile phone shows up - NOT a phantom phone or phones  CONNECTED to our network ONLY after the D7000 wifi in enabled!!!!

Our neighbour connects to our wifi without a problem with HIS phone!!

Speaks for itself really.

Nothing shows up untill WIFI IS ON!

That is not a windows problem it is a NETGEAR problem.

I know about the support or lack of support with 3rd party firmwear for other products ie ROUTER....

ALL security measures HAVE been correctly set up ok! 

STEP BY STEP.

Don't patronise.

This product is going back. A full refund is already  in process.

THANK you.


 

 

As mentioned above, this is a Windows thing. If the phone is associated with your network, but does not have an IP address in your network, then it is not connected to your network. Look at your router's connected device list, to see if they have an IP address. Here's a link on this discussion. It's an old issue.

 

https://community.netgear.com/t5/Nighthawk-WiFi-Routers/New-R7000-is-allowing-unknown-telephones-to-...

Message 7 of 10

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language


@netwrks wrote:

As mentioned above, this is a Windows thing. If the phone is associated with your network, but does not have an IP address in your network, then it is not connected to your network. Look at your router's connected device list, to see if they have an IP address. Here's a link on this discussion. It's an old issue.

 

https://community.netgear.com/t5/Nighthawk-WiFi-Routers/New-R7000-is-allowing-unknown-telephones-to-...


 

Yup. That was my theory, thanks for finding the link to the earlier discussion. But I fear that we have someone who isn't keen to listen to advice.

 

I did have other thoughts on the issue, like looking to see if a guest network was active, but the answer I got to what I thought were reasonable questions and suggestions, all based on past discussions around here, and the fact that they have returned the device, persuaded me that there wasn't much point in continuing the conversation.

 

 

Message 8 of 10
netwrks
Master

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

I think someone's tin foil hat may be on a bit tight.. 😉

Message 9 of 10

Re: D7000 hacked? (1)lost access (2)reset (3)got access (4)firmware update not working + language

Indeed. Several tell-tale signs.
Message 10 of 10
Discussion stats
  • 9 replies
  • 4292 views
  • 1 kudo
  • 4 in conversation
Announcements

Orbi WiFi 7