× Introducing the Orbi 970 Series Mesh System with WiFi 7 technology. For more information visit the NETGEAR Press Room.
Orbi WiFi 7 RBE973
Reply

XR1000 - Security issues/how to?

tyrelever
Aspirant

XR1000 - Security issues/how to?

Hi all.

Does anyone know how to

1) Fully disable WPS.

2) Configure the admin page for HTTPS, PKI cert or self-signed if we must.

3) Disable port 80 on the admin page

4) Change the admin page from basic auth to form-based or something better than this.

 

Security on this thing is worrying.  What else is sketchy.

 

Message 1 of 4
Netduma-Fraser
NetDuma Partner

Re: XR1000 - Security issues/how to?

Hello, to answer your questions:

1. Not that I am aware, though you can set a router PIN to make WPS more secure
2. No and the interface does not work well when trying to force HTTPS
3. No
4. No

Sorry if that's not the answers you were looking for, they're out of our scope so I would suggest making a ticket with Netgear to suggest them as additions.
Message 2 of 4
tyrelever
Aspirant

Re: XR1000 - Security issues/how to?

Thanks for the reply.

Please forgive me, is this not Netgear?

 

I admit, I am perplexed that a security device OS can't use HTTPS because it doesn't work well.  This is simply insane in these days.

Can you please tell me what other functions are unencrypted?  

Also, is there really no way to disable WPS?  Surely this is something we should be able to do.

 

Message 3 of 4
Netduma-Fraser
NetDuma Partner

Re: XR1000 - Security issues/how to?

This is a community forum for Netgear but you are unlikely to receive an actual response from Netgear as they have separate support channels that they take care of. However, myself and my colleague Liam work for Netduma who created DumaOS and do respond to every post. That being said, the entire settings part of the router is Netgear software and not something we have created.
The router is a local device, only accessible by your local network and there aren't any sensitive details that would be at risk, I do understand HTTPS would be preferable, just due to the way of software works it is hindered by HTTPS. I'm not one of the developers so I don't have a more technical answer for you on that one. I don't think you can disable WPS unfortunately, someone has asked this before and the only thing to do is set the pin.
Message 4 of 4
Discussion stats
  • 3 replies
  • 733 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi WiFi 7