Orbi WiFi 7 RBE973
Reply

R6900: Security Issue found by Avast

Riley78
Guide

R6900: Security Issue found by Avast

I updated my Avast free antivirus to the current build and ran the Wi-Fi inspector. I had ran it recently and it found no problems. But now it reads:

"Your router or Wi-Fi hotspot is vulnerable to network attacks!
We have found vulnerabilities in your router or Wi-Fi hotspot that can be used by attackers to hack into your network.

Description
Our scan found a vulnerability on your router or Wi-Fi hotspot device. Your device contains a problem that can be misused by cybercriminals to break into your network and compromise your security and privacy.

Android devices used as a Wi-Fi hotspot can be also affected.

Solution
Some of the vulnerabilities may be patched in new versions of the device firmware or system update. Applying the latest firmware or system update may solve the issue.

Consult your device's manual for instructions. If an update adressing the vulnerability issue is not available, contact your devices's vendor or manufacturer to provide an update as soon as possible.

Details
We have identified the following problem with your router or Wi-Fi hotspot device:

DnsMasq heap buffer overflow vulnerability
Severity: High

Reference: CVE-2017-14491  http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14491

Google Security Blog: https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

Description:
The affected device's DNS service is running an outdated version of the DnsMasq software which is known to have a heap buffer overflow vulnerability.

Impact:
Any device connected to your network, including computers, phones, tablets, printers, security cameras, or any other networked device in your home or office network, may have an increased risk of compromise.

Recommendation:
The issue was fixed in DnsMasq software version 2.78, released in October 2017.

To solve the vulnerability on your device, apply the firmware or system update that contains DnsMasq software version 2.78 or higher provided by your device's manufacturer.

If an update addressing the vulnerability is not yet available for your device, you can secure your router or Wi-Fi hotspot with a strong password to minimize risks imposed by the vulnerability. We also advise you not to visit suspicious websites or run software from questionable sources".

 

I am running firmware version V1.0.1.44_10.0.28, and there is nothing newer.

 

I would appreciate any feedback on how to deal with this. 

 

Model: R6900|Nighthawk AC1900 Smart WiFi Router
Message 1 of 12

Accepted Solutions
Riley78
Guide

Re: R6900: Security Issue found by Avast

So with the just released firmware version 1.0.2.4,  dnsmasq is finally updated to 2.78. 

It only took one full year.

View solution in original post

Message 12 of 12

All Replies
Riley78
Guide

Re: R6900: Security Issue found by Avast

Thanks for the reply. I think you are saying there is no problem?  I also posted this to the Avast forum. I was directed to this post: https://forum.avast.com/index.php?topic=215664.msg1449477#msg1449477 .

I tested the router using the command listed, and it seems there is a security issue.

C:\>nslookup -type=txt -class=chaos version.bind 192.168.1.1
Server: UnKnown
Address: 192.168.1.1

version.bind text =

"dnsmasq-2.15-OpenDNS-1"

 

So if my understanding is correct, will Netgear patch it? Do I need to alert them?

Message 2 of 12
Riley78
Guide

Re: R6900: Security Issue found by Avast

How do I alert Netgear, or will someone else take care of it?

Message 3 of 12

Re: R6900: Security Issue found by Avast

So, it is Avast's turn to join the roster of AV companies spreading scare stories around the planet.

 

avast Search results

 

These tales may or may not be valid. (They aren't usually.) But as you'll see from that search this is a pretty common issue. The usual resolution is for Netgear to tell Avast to get its act together.

 

 

Message 4 of 12
JamesGL
Master

Re: R6900: Security Issue found by Avast

Hi Riley78,

 

Thank you bringing this up. Please check the link below to report vulnerabilities.

 

https://www.netgear.com/about/security/default.aspx

 

 

Message 5 of 12

Re: R6900: Security Issue found by Avast

Indeed. I didn't try to brush it under any carpet, which is why I suggested that it is down to Netgear to talk to Avast and deal with the issue.

 

I just wanted to let the person who posted the message know that this is not the first time that Avast has cropped up here as a source of these warnings.

 

On balance, most of these reports turn out to be "fake news", but you should never ignore them. Let Netgear know. But do so in the knowledge that you may not face any truly nasty immediate risk.

 

The message has to be, be careful but don't panic.

 

Message 6 of 12

Re: R6900: Security Issue found by Avast


@Case850 wrote:

@michaelkenward

Try running this command from windows PC to each of your modem-routers. IP adress may be different to 192.168.1.1 for your modem-routers

 

C:\>nslookup -type=txt -class=chaos version.bind 192.168.1.1

 

That alone probably wouldn't tell me much about my security status.

 

At the moment, I am running non-standard firmware as a part of a Netgear beta test. I can't say what it is all about, beyond that it is a security thing for something that Netgear has already announced. Perhaps you are in the same beta program.

 

If this Avast thing is enough to warrant updates to all Netgear's firmware, I think we can safely expect to see an increase in those "new firmware broke my router" messages.

 

 

Message 7 of 12
Riley78
Guide

Re: R6900: Security Issue found by Avast

James, could you or one of the mods please either submit the issue or find out if Netgear is working on it?  I did not submit a report. I found the website confusing.

My R6900 with latest firmware runs "dnsmasq-2.15-OpenDNS-1"

Thanks

 

This is what they need to know: CVE-2017-14491

https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html

Avast sends me to: https://help.avast.com/en/av_free/17/hns/cve-2017-14491.html

Message 8 of 12
Blanca_O
NETGEAR Moderator

Re: R6900: Security Issue found by Avast

Hi Riley78,

 

We encourage users to report such vulnerability on the link below for proper channeling: 

https://www.netgear.com/about/security/default.aspx

 

A new firmware is released for this model and fixes for security issues are included. Here's the release notes: 

https://kb.netgear.com/000058221/R6900-Firmware-Version-1-0-1-46

 

Regards,

 

Blanca 
Community Team

Message 9 of 12
Riley78
Guide

Re: R6900: Security Issue found by Avast

I am running that firmware and it does not update dnsmasq.

Message 10 of 12
Blanca_O
NETGEAR Moderator

Re: R6900: Security Issue found by Avast

Hi Riley78, 

 

I got a confirmation from Engineering team that R6900 is not affected by the vulnerability. 

 

Regards,

 

Blanca 
Community Team

Message 11 of 12
Riley78
Guide

Re: R6900: Security Issue found by Avast

So with the just released firmware version 1.0.2.4,  dnsmasq is finally updated to 2.78. 

It only took one full year.

Message 12 of 12
Top Contributors
Discussion stats
  • 11 replies
  • 10605 views
  • 3 kudos
  • 4 in conversation
Announcements

Orbi WiFi 7