Reply
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
R7500 Vulnerable to NetUSB Bug
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-05-26
05:44 AM
2015-05-26
05:44 AM
R7500 Vulnerable to NetUSB Bug
Hello,
After reading this article, I got kind of worried as I use the R7500 as my primary defense:
'Researchers at SEC Consult discovered that the NetUSB driver is plagued by a kernel stack buffer overflow vulnerability (CVE-2015-3036) that can be exploited by an unauthenticated attacker to execute arbitrary code or cause a denial-of-service (DoS) condition.'
A little bit lower I see the statement: 'NETGEAR told us, that there is no workaround available, the TCP port can't be firewalled nor is there a way to disable the service on their devices'
Please fix this, I feel unprotected at the moment.
Cheers, Laszlo
Message 1 of 3
Labels:
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-05-26
09:40 AM
2015-05-26
09:40 AM
Re: R7500 Vulnerable to NetUSB Bug
Take a look at this please;
http://kb.netgear.com/app/answers/detail/a_id/28393
http://kb.netgear.com/app/answers/detail/a_id/28393
____________________________
Working on behalf of Netgear
My name is Andy
Working on behalf of Netgear
My name is Andy
Message 2 of 3
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-05-26
12:36 PM
2015-05-26
12:36 PM
Re: R7500 Vulnerable to NetUSB Bug
Hi Andy,
Thank you for your swift response. It is good to read that NetGear is working on a fix to deal with this.
It is a bit strange that not all devices affected are mentioned. For other readers, refer to: https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150519-0_KCodes_NetUSB_Kern....
If there is a mailing list I could join to read more about potential security vulnerabilities regarding the R7500, please let me know.
Thanks again! Laszlo
Thank you for your swift response. It is good to read that NetGear is working on a fix to deal with this.
It is a bit strange that not all devices affected are mentioned. For other readers, refer to: https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150519-0_KCodes_NetUSB_Kern....
If there is a mailing list I could join to read more about potential security vulnerabilities regarding the R7500, please let me know.
Thanks again! Laszlo
Message 3 of 3
Top Contributors
User | Count |
---|---|
11 | |
10 | |
6 | |
3 | |
3 |