Orbi WiFi 7 RBE973

Re: R7000 & R6400 Vulnerability Note VU#582384

ElaineM
NETGEAR Employee Retired

Re: R7000 & R6400 Vulnerability Note VU#582384

@kochin Thank you very much for the confirmation that the beta fixed it.

 

We appreciate your continued patience as we work on this.

Message 26 of 35
Wyle008
Aspirant

Re: R7000 & R6400 Vulnerability Note VU#582384

Hi

 

Just update firmware of my R7000 Router to beta 1.0.7.6 and would like to know if others also experience the following behaviour (used MS Edge for testing):

 

1. Go to router start page (in my case 192.168.1.1) and click cancel, meaning do not enter username and password

 

2. Enter the poc url http://192.168.1.1/cgi-bin/;telnetd$IFS-p$IFS'45' into the address bar and click cancel when it asks for username and password. 404 not found message appears

 

3. Entering again router start page 192.168.1.1 doesn't ask for username and password know and I am automatically logged in to the management console?!

 

Is this working as desgined or still a bug in the beta firmware?

 

Model: R7000|Nighthawk AC1900 Dual Band WiFi Router
Message 27 of 35
ElaineM
NETGEAR Employee Retired

Re: R7000 & R6400 Vulnerability Note VU#582384

Perhaps a cached page? Did you delete browsing history and cached?

Though I don't have Edge, I'm not getting this on IE, Firefox and Chrome. 

Message 28 of 35
jrgreenman
Tutor

Re: R7000 & R6400 Vulnerability Note VU#582384

Will the updated firmware wipe out all my settings? The technote says:

 

"Write down all the settings which you changed from the default values, since you may need to re-enter them manually."

 

But does it actually wipe them out? And, if so, will backing up the settings w/ my current firmware allow me to successfully restore them after flashing the beta firmware?

 

I have a pretty large port forwarding and DHCP reservation tables and would need ot set aside considerable time to re-enter everything if I had to.

Message 29 of 35
mdgm-ntgr
NETGEAR Employee Retired

Re: R7000 & R6400 Vulnerability Note VU#582384

You should prepare just in case to be able to re-enter your settings manually e.g. if you need to do a factory reset after the upgrade.

 

I had no problems but then I have a very simple configuration on my R7000.

Message 30 of 35
jrgreenman
Tutor

Re: R7000 & R6400 Vulnerability Note VU#582384

That's good advice, but I'm really wondering if others have flashed the beta and can confirm that their settings remained intact or, at least, that the new firmware is able to successfully restore settings backed up with the prior firmware.

 

You guys must have tested this in the lab, yes? Did it work for you?

Model: R7000|Nighthawk AC1900 Dual Band WiFi Router
Message 31 of 35
kochin
Apprentice

Re: R7000 & R6400 Vulnerability Note VU#582384

@Wyle008

I do recall a similar experience with Chrome browser right after I updated to the beta firmware. As @ElaineM said, it probably was a cached page. That was my immediate guess when I saw my router showed me the administration page without loggin in, and I re-started my brower and then was asked to log into the router.

 

Message 32 of 35
kochin
Apprentice

Re: R7000 & R6400 Vulnerability Note VU#582384

@jrgreenman

After update to the beta firmware, I verified that all my settings on the router are intact. The settings I had customized and tuned to my likings are

  • Internet Setup
  • Wireless Setup
  • LAN Setup
  • Guest Network
  • Device Name
  • ReadySHARE Storage
  • Wireless Settings
  • Port Forwarding
  • VPN Service
  • Remote Management

I can report all those settings have not been changed.

 

Message 33 of 35
jrgreenman
Tutor

Re: R7000 & R6400 Vulnerability Note VU#582384

Confirmed! Router is updated and prior preferences remained.

 

Thanks for the reply. Gave me just the confidence I needed to take the plunge.

 

But yes, I wrote everything down prior anyway. 🙂

Message 34 of 35
ElaineM
NETGEAR Employee Retired

Re: R7000 & R6400 Vulnerability Note VU#582384

Hi All,

 

The Security Advisory for VU 582384 has been updated.

 

Also, for more information and update see the thread below.

 

https://community.netgear.com/t5/Nighthawk-WiFi-Routers/Two-leading-Netgear-routers-are-vulnerable-t...

Message 35 of 35
Top Contributors
Discussion stats
  • 34 replies
  • 17038 views
  • 20 kudos
  • 12 in conversation
Announcements

Orbi WiFi 7