NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
JohnWDarby
Jun 28, 2016Initiate
Web GUI Password Recovery and Exposure Security Vulnerability
I would like to point out to Netgear that their password recovery options are woefully insecure. I followed their advice to turn on Password Recovery but immediately aborted, Every single question ca...
- Jun 29, 2016
Hi All,
Here is the KB article for the said vulnerability. You can check for the specific model number that is affected.
TheEther
Jun 30, 2016Guru
hawki, it's not clear to me what you are seeing when you attempt to log into the C6300. It should look like this (complements of setuprouter.com):

Then you should click on the Advanced tab at the top, then Administration on the side and finally Set Password, similar to this:

As far as firmware upgrades is concerned, the C6300 is a cable router modem. It is frequently the case for such devices that firmware upgrades are available only through your ISP. If the C6300 is not officially supported by your ISP, then you are outta luck. :smileysad:
hawki
Jun 30, 2016Apprentice
Th
TheEther wrote:hawki, it's not clear to me what you are seeing when you attempt to log into the C6300. It should look like this (complements of setuprouter.com):
Then you should click on the Advanced tab at the top, then Administration on the side and finally Set Password, similar to this:
As far as firmware upgrades is concerned, the C6300 is a cable router modem. It is frequently the case for such devices that firmware upgrades are available only through your ISP. If the C6300 is not officially supported by your ISP, then you are outta luck. :smileysad:
That is what I see. When I go to the set password page there is NO box to check to "Enable PW Recovery when I go to the set password page. I will check with my ISP. Cox has two categories of compatible modems: 1) Cox Preferred Devices; 2) Additional Cox Recommended DOCSIS 3.0 Devices. My C6300 falls under category 2. My modem works fine and delivers more than my guaranteed 100Mbps - It gives me 130Mbps
I will check with Cox, but I doubt they will have a firmware update. In the past all my firmware updates have been downloaded from Netgear after a pop-up appears asking me if I want the upgrade. But firmware squirmware - why do I not have the box to enable PW recovery? Is that something new?
Windows also searched The Net for a firmware update and said I had the latest as does my Genie.
Weird - so now I don't know if I have the vulnerability or not.
Thanks again for your taking the time to try to help :-)
hawkeye