//
× We have been made aware of an issue with Remote Management functionality not working when using the Orbi or Nighthawk app. This issue should now be resolved. Please create new discussion in the Apps and Services forum if you are still experiencing issues.
× We have been made aware of an issue with Remote Management functionality not working when using the Orbi or Nighthawk app. This issue should now be resolved. Please create new discussion in the Apps and Services forum if you are still experiencing issues
× We are experiencing an outage of our ReadyCloud service and are working to resolve the issue..
× NETGEAR Holiday Deal Guides for: Home Networking, Business Networking & Gaming!

This topic has been closed to new posts due to inactivity. We hope you'll join the conversation by posting to an open topic or starting a new one.

NETGEAR ® COMMUNITY
  • Downloads
  • MyNETGEAR
  • Community
  • Support
  • Netgear
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • Netherlands (Dutch)
    • Sweden (Svenska)
    • United States (English)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • English
  • /
  • NETGEAR Forum
  • /
  • Home Networking
  • /
  • Orbi WiFi System
  • /
  • Orbi
  • /
  • Admin ID Security Risk
Log In
Join Now
  • Community Home
  • Community Browser:
  • NETGEAR Website
  • Support
  • Downloads
  • MyNETGEAR
Log In
  • English
  • /
  • NETGEAR Forum
  • /
  • Home Networking
  • /
  • Orbi WiFi System
  • /
  • Orbi
  • /
  • Admin ID Security Risk
  • Join Now
  • |
  • Log In
  • |
  • Help

Start a New Discussion

Discussion stats
  • 5 replies
  • ‎2019-06-12 08:03 PM
  • 735 views
  • 0 kudos
  • 4 in conversation
    • michaelkenward
    • CrimpOn
    • Ragar99
    • gslabbert5119
Announcements

NETGEAR Holiday Deal Guides for: Home Networking, Business Networking & Gaming!

WiFi 6 Frequently Asked Questions

Check Out What's New With NETGEAR Armor!

Recap of National Cyber Security Awareness Month - #BeCyberSmart

Are You Safe From Online Threats? - Live Event

Cybersecurity & Tips for Protecting Your Home Network

The History & Future of WiFi - Infographic

What is WiFi 6? #NowAtNETGEAR

Do More This Summer with Orbi Voice

Top Contributors
User Count
FURRYe38
FURRYe38 Guru
39
CrimpOn
CrimpOn Master
38
VAJim
VAJim Hero
14
SW_
SW_ Prodigy
11
plemans
plemans Master
8
See All
Orbi Mesh WiFi

Welcome to the Orbi Community


Smarten Up Your WiFi Click to Buy Orbi
Reply
Topic Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • All forum topics
  • Previous Topic
  • Next Topic
Highlighted
gslabbert5119
gslabbert5119 Aspirant
Aspirant
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-12 08:03 PM
‎2019-06-12 08:03 PM

Admin ID Security Risk

How is it possible that a company the size of Netgear, can leave a huge security hole in their router - Orbi firmware.
Not being able to disbale the admin ID  of "admin" removes a layer of security as the userid "admin" is a well known username, now all a hacker has to deal with is hacking the password and not have to trouble themselves with the userid. This makes the task of hacking a system exponentially easier.

This is my first Netgear system, and I have always used Linksys, where I have been able to not only add a different admin id that is secret and known only to me (just like a password), but linksys has the ability to assign mulitple admin id's so that various network admins can have access to the config and make changes.

I would go back to linksys, if it were not for the fact that the linksys meshed network does not have the range of the Orbi network, and I am stuck with a system that has a huge security hole in my opinion.

Any suggestions or ideas how i can bring this to Netgear with sufficient vigor that they will include this in a soon to be released  update?

Model: RBR50|Orbi AC3000 Tri-band WiFi Router
Message 1 of 6
0 Kudos
Reply
CrimpOn
CrimpOn Master
Master
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-12 11:04 PM
‎2019-06-12 11:04 PM

Re: Admin ID Security Risk

This is correct.  If a person is able to (1) gain physical access to an Orbi LAN port, or (2) break the WiFi password, then only the (complicated?) administrative password securess the router.

 

It may be possible to telnet into the Orbi and change the name from "admin" to something else:

https://community.netgear.com/t5/Orbi/How-to-change-Admin-as-UserID-on-Orbi-RBR50/m-p/1695642#M50858

 

(Disclaimer: I have not actually done this myself.  If you are able to do this *successfully*, it would be nice to have confirmation that "it worked")

Message 2 of 6
0 Kudos
Reply
michaelkenward
Guru michaelkenward Guru
Guru
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-13 08:14 AM
‎2019-06-13 08:14 AM

Re: Admin ID Security Risk


@gslabbert5119 wrote:


Not being able to disbale the admin ID  of "admin" removes a layer of security as the userid "admin" is a well known username, now all a hacker has to deal with is hacking the password and not have to trouble themselves with the userid. This makes the task of

 

Netgear is not alone in this "crime against humanity".

 

In years of watching this place, I cannot remember seeing any reports that people have accessed a device by breaking that security.

 

After all, as @CrimpOn says, someone has to all but break into your house to get local access to your hardware.

 

Were this really that dangerous a move, the world, and this place, would be awash with complaints and reports of hacked systems. It has come up from time to time as a "feature request", but even those have gone away.

 

Anyone seriously paranoid, you could always intert a modem/router in front of an Orbi system and put that into AP mode. That would add one layer of security.

 

 

Just another user.
My network DM200 -> R7800 -> GS316 -> PL1000 -> Orbi RBR40 -> Orbi RBS50Y -> RBS40V
Message 3 of 6
0 Kudos
Reply
Ragar99
Ragar99 Luminary
Luminary
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-13 09:20 AM
‎2019-06-13 09:20 AM

Re: Admin ID Security Risk


@michaelkenward wrote:

@gslabbert5119 wrote:


Not being able to disbale the admin ID  of "admin" removes a layer of security as the userid "admin" is a well known username, now all a hacker has to deal with is hacking the password and not have to trouble themselves with the userid. This makes the task of

 

Netgear is not alone in this "crime against humanity".

 

In years of watching this place, I cannot remember seeing any reports that people have accessed a device by breaking that security.

 

After all, as @CrimpOn says, someone has to all but break into your house to get local access to your hardware.

 

Were this really that dangerous a move, the world, and this place, would be awash with complaints and reports of hacked systems. It has come up from time to time as a "feature request", but even those have gone away.

 

Anyone seriously paranoid, you could always intert a modem/router in front of an Orbi system and put that into AP mode. That would add one layer of security.

 

 


Belittling someone on the basis of "some other vendors do it also" is incredibly ignorant when it comes to security.  

Message 4 of 6
0 Kudos
Reply
gslabbert5119
gslabbert5119 Aspirant
Aspirant
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-13 11:21 AM
‎2019-06-13 11:21 AM

Re: Admin ID Security Risk

Ok, so just because as far as you know a netgear router or Orbi system has never been hacked, does not mean it has not happened. Further consumers are a small portion of netgears business and there a many not so small businesses using home type routers and networks for their comms. In fact a rather large mortgage company that was taken of by the #3 bank at the time, had netgear routers and your and my personal info was at risk there, so it does affect you, or can, and we know that they were hacked, we found evidence when we did the conversion.
Simply put just because you live in a place where you can leave the keys to your kingdom does not mean that you should and eventually it will be stolen, and no I am not that paranoid, all I ask is that I am able to practice safe security as is mandated by the security industry.

Not fixing the issue is shortsighted, and one once of prevention is better than 10 lbs of cure.

 

Message 5 of 6
0 Kudos
Reply
CrimpOn
CrimpOn Master
Master
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-06-13 11:58 AM
‎2019-06-13 11:58 AM

Re: Admin ID Security Risk

In addition to the administrative user name, Netgear also does not secure the administrative web site, i.e. uses "http" rather than "https".  IF someone were to snoop on an Orbi long enough to break the WiFi encryption, and IF the Orbi administrator accessed the web site over WiFi while the snoop was recording, it would be possible to gather the Orbi login password.  My Netgear Nighthawk router is exactly the same.

 

I, personally, handle this vulnerability by using only a wired computer for administration.

Message 6 of 6
0 Kudos
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
Need More Help?
  • Contact Support
  • About Us
  • Investor Relations
  • Contact us
  • Careers
  • Sign Up
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • Netherlands (Dutch)
    • Sweden (Svenska)
    • United States (English)

© 1996-2019 NETGEAR®