- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Re: Is R6900 router affected by new (12/12) vulnerability?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is the R6900 (Costco variant of the R7000--slightly different) affected by the newfound vulnerability. If so, will the R7000 firmware upgrade work to protect it?
Thanks,
FuelScience
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Follow up:
I installed the beta firmware for my Nighthawk R6900 and it appears to have fixed the cgi-bin vulnerability, and the router appears to be working with no loss of configfuration after the reboot.
So far, a happy ending...
All Replies
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
The R6900 uses its own firmware. Don't try installing firmware for a different model.
The R6900 is not on the list of known affected models.
We mentioned in the Security Advisory "NETGEAR is continuing to review our entire portfolio for other routers that might be affected by this vulnerability. If any other routers are affected by the same security vulnerability, we plan to release firmware to fix those as well."
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
Thanks. The second link gave an error message, but the first returned the following:
Linux R6900 2.6.36.4brcmarm+ #17 SMP PREEMPT Sat Jun 27 18:29:04 CST 2015 armv7l unknown
I'm assuming that means that my R6900 is indeed affected.
FuelScience
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
Yes. I can see we have already updated the Security Advisory to reflect this. We don't have a beta firmware ready yet but we will update the Security Advisory when we do.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
I saw this vulnerability on the news. I wasn't sure I was affected until I ran this:
http://192.168.1.1/cgi-bin/;reboot
And sure enough, my router rebooted! This is an amazingly easy exploit.
I found the beta code on the website to fix the problem, but it looks like it is a little risky, based on the description. So I called NetGear support and explained the problem. They ask me for my serial number. It turns out that I'm about 1 month past the free warrentee period, so the tech refused to even talk with me about the problem unless I paid for support.
Unbelievable. Well, I will just install the beta code and hope for the best. I work from home full time, so if it does not work, I will be scrambling for a replacement router.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Follow up:
I installed the beta firmware for my Nighthawk R6900 and it appears to have fixed the cgi-bin vulnerability, and the router appears to be working with no loss of configfuration after the reboot.
So far, a happy ending...
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
I installed the new firmware as well this morning, and all appears to be working well.
FuelScience
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Is R6900 router affected by new (12/12) vulnerability?
Thank you for the confirmation that the firmware fixed it.
Should you have any more concerns or wants an update regarding this issue, please see the thread below.
• Introducing NETGEAR WiFi 7 Orbi 770 Series and Nighthawk RS300
• What is the difference between WiFi 6 and WiFi 7?
• Yes! WiFi 7 is backwards compatible with other Wifi devices? Learn more