× NETGEAR will be terminating ReadyCLOUD service by July 1st, 2023. For more details click here.
Orbi WiFi 7 RBE973
Reply

ReadyNAS OS 6.10.9 now available – With almost no info

eton
Luminary

Re: ReadyNAS OS 6.10.9 now available – With almost no info

It took a long while, but now there is at least some information about version 6.10.9.


https://kb.netgear.com/000065542/Security-Advisory-for-Multiple-Vulnerabilities-on-ReadyNAS-OS-6-PSV...

Published: 10 November 2023

 

Associated PSVs:

PSV-2023-0015
PSV-2023-0016
PSV-2023-0017

 

Where can I find more information? What are the changes in 6.10.9?
And where can I read the details about PSV-2023-0015, PSV-2023-0016 and PSV-2023-0017?

 

What does PSV mean? Netgear doesn't explain it. Is it an abbreviation for Product Security Vulnerability?

 

 

Message 26 of 32
StephenB
Guru

Re: ReadyNAS OS 6.10.9 now available – With almost no info


@eton wrote:

 

What does PSV mean? Netgear doesn't explain it. Is it an abbreviation for Product Security Vulnerability?

 


Probably, but maybe could be Platform Security Validation (which is an methodology to assess security).  Looks like Netgear published it, as there are no CVEs reported against ReadyNAS after 2018.

 

There is a bit more info on these here:

But in general, if a vendor provides a security update, you should install it.

 


@eton wrote:

What are the changes in 6.10.9?


They only mention the security patches here:

I've been running it for quite a while now, and havent seen any behavior changes from 6.10.8.

Message 27 of 32
GGITech
Apprentice

Re: ReadyNAS OS 6.10.9 now available – With almost no info

Has anyone else had any issues with apps not installing?

I had Calendar and Contacts installed with 6.10.4. The device was for testing and redundancy of another 102, and I repurposed it.

Now with 6.10.8, then 6.10.9 hardly ANY apps will install.

What I did:

I did a complete factory reset, OS install, and have a running NAS with new drives.

As I said, everything is functioning correctly and I can copy files, add users, create shares, et al.

I have not tired every app, as I got tired of trying and failing. Here is a list of what actually fails to install:

  • ajaxplorer
  • asterisk
  • bbindr6
  • bzeetr6
  • contacts and calendar
  • couch patato
  • ddclientr6
  • dns server
  • drupal
  • glpi
  • idrive
  • joomla
  • koken
  • linux-dash
  • logitech media server

Sometimes they fail inside the Gui and notify, other times they just seem to crash the GUI and force a new login.

The only apps that seem to install are 

  • istat, it does resets the admin gui, and fore relogin
  • kernal plus, gui resets
  • istat nt, installs correctly, shows dialog, back to gui

Any idea what is going on? I have considered rolling back to 6.10.4 but have no idea if this will fix the issue.

It is quite a hassle to roll back with the horrid build process of the USB and having to manually do everything, so I have not done that, and thought I might ask first. 

At this point, I might be obvious with the deprecation of the platform as mentioned by its lack of updates, even official posting of the latest firmware, that I should just continue to use them as a storage point and build another device for the few apps that were flawless to run on them quietly.

 

Any input is appreciated, if this needs its own thread, let me know and I will start one.

 

Message 28 of 32
StephenB
Guru

Re: ReadyNAS OS 6.10.9 now available – With almost no info


@GGITech wrote:

Has anyone else had any issues with apps not installing?

 

Any input is appreciated, if this needs its own thread, let me know and I will start one.

 


See this thread:

The issue is that Debian 8 (the OS used by your ReadyNAS) is no longer supported, and has been archived by the Debian community.  There are some changes you need to make to the NAS to tell it to access the archives.

Message 29 of 32
GGITech
Apprentice

Re: ReadyNAS OS 6.10.9 now available – With almost no info

Specifically #37 in that post it seems...I just ran across that.

Yeah I get 8 has been deprecated, but with the known internal dependence, I never thought they would depend on external sources for the custom rolled version....Figures, as that is more bad planning on NG's part.

 

I appreciate the point to that...I will start digging.

 

 

Message 30 of 32
StephenB
Guru

Re: ReadyNAS OS 6.10.9 now available – With almost no info


@GGITech wrote:

I never thought they would depend on external sources for the custom rolled version....Figures, as that is more bad planning on NG's part.

 


Actually I think using the official repositories whenever you can is the right strategy.

 

That said, IMO Netgear should have done a software release (at least a hot fix) to change the apt config.  They also should have done a release to fully remove ReadyCloud from the NAS.  Hopefully they will eventually get around to do that.

Message 31 of 32
eton
Luminary

Re: ReadyNAS OS 6.10.9 now available – With almost no info

Thanks @StephenB 

 

https://www.cybersecurity-help.cz/ is a great resource. I've never visited that site before. I don't know much about bug bounty hunting.

 
Message 32 of 32
Top Contributors
Discussion stats
  • 31 replies
  • 4097 views
  • 2 kudos
  • 7 in conversation
Announcements