× Introducing the Orbi 970 Series Mesh System with WiFi 7 technology. For more information visit the NETGEAR Press Room.
Orbi WiFi 7 RBE973
Reply

WNDR4000 - Blocking Admin Access After Latest Security Update

markman
Aspirant

WNDR4000 - Blocking Admin Access After Latest Security Update

I updated the firmware in response to a notice I received from Netgear about a security fix.  Now, every time I adjust the various settings and the router reboots it blocks my access to the admin page (I get the notice that another device is logged in).  

 

I have tried setting a static IP address on my computer, connecting with a wired connection, using the web interface, using the Genie app, etc.  I have downloaded another copy of the firmare and reflashed, factory reset several times with the same result - I get "blocked" once I adjust the router settings and it reboots.

 

The router is working properly but I cannot manage it (it did not behave this way prior to that new firmware update).

 

Any ideas, aside from downgrading the firmware?

 

Thank you in advance.

Model: WNDR4000|N750 Wireless Dual Band Gigabit Router|EOL
Message 1 of 10

Accepted Solutions
CDC86
Initiate

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

I just applied the latest Firmware (1.0.2.6) update as well, I don't recall the previous version, but it was a much earlier version 1.0.0 (not sure of the last digits).   After the update and installation completed (which was applied by direct ethernet connection, i.e. not WIFI), I can no longer connect to the web Administration Page via the default gateway IP address.  What's odd is all my setups remained in tact after the Firmware update was applied, including the authentication credentials.  If I run an IPCONFIG, the settings for DHCP, Gateway, etc are all as was on my directly connected laptop.  But, when I first re-open the admin page using the default gateway IP address and authenticating I receive the message "You are currently logged in from another device. There can be only one device logged in at a time. If you log in from this device, the other device will be logged out. Do you want to proceed?", as I was in the same, or original browser session when the firmware update was applied I clicked "yes" to proceed, after which the connection fails to open the adminstration page. I tried different browsers (Chrome, IE), still no access.

 

I powered down the router, restarted, entered gateway IP address to connect to admin page, authenticated as requested and the same warning message appears ... "You are currently logged in from another device. There can be only one device logged in at a time. If you log in from this device, the other device will be logged out. Do you want to proceed?"  But, this time, choose "No" and the response page displayed a conflicting dynamic IP address, which is different from the dynmamic IP address assigned to the laptop. which I applied the firmware upgrade from.  On a whim, I turned off my WIFI connection on my cell phone.  I tried to ping the new, conflicting IP address assigned and the request timed out. I then tried to connect to the administration page using the default gateway IP address, SUCCESS.

 

Bottom line, check what other device may be connected, which I was able to determine by choosing "No" to the Do you want to proceed?

View solution in original post

Model: WNDR4000|N750 Wireless Dual Band Gigabit Router|EOL
Message 4 of 10

All Replies
antinode
Guru

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

> I updated the firmware [...]

   To which version?  (From?)

> [...] every time I adjust the various settings [...]

   Which "the various settings" are you adjusting (to what)?

> I have tried setting a static IP address on my computer, [...]

   Which "a static IP address"?

> Any ideas, aside from downgrading the firmware?


   That would certainly be an interesting experiment to run.

Message 2 of 10
markman
Aspirant

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

I updated the firmware to the latest version WNDR4000-V1.0.2.6_9.1.87.chk

I don't recall the previous version, but it was the most recent prior to this security update (I imagine that this model woud not normally have any additional updates due to its age).

 

The various settings would be SSID and wireless password.  I normally limit the DHCP scope as well, but I can't get that far with the configuration as the router resets itself after setting up the security.  Once the router resets, I cannot access the admin web page nor connect via Genie.

 

I set a static IP address on my PC (e.g. 192.168.1.10) so that <hopefully> the router would not think that a different device is trying to log in.

 

Again, the router is functional but I cannot administer it after the first reset.

 

This is clearly some kind of glitch with the latest firmware (I might give dd-wrt a shot before throwing this one away).

Message 3 of 10
CDC86
Initiate

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

I just applied the latest Firmware (1.0.2.6) update as well, I don't recall the previous version, but it was a much earlier version 1.0.0 (not sure of the last digits).   After the update and installation completed (which was applied by direct ethernet connection, i.e. not WIFI), I can no longer connect to the web Administration Page via the default gateway IP address.  What's odd is all my setups remained in tact after the Firmware update was applied, including the authentication credentials.  If I run an IPCONFIG, the settings for DHCP, Gateway, etc are all as was on my directly connected laptop.  But, when I first re-open the admin page using the default gateway IP address and authenticating I receive the message "You are currently logged in from another device. There can be only one device logged in at a time. If you log in from this device, the other device will be logged out. Do you want to proceed?", as I was in the same, or original browser session when the firmware update was applied I clicked "yes" to proceed, after which the connection fails to open the adminstration page. I tried different browsers (Chrome, IE), still no access.

 

I powered down the router, restarted, entered gateway IP address to connect to admin page, authenticated as requested and the same warning message appears ... "You are currently logged in from another device. There can be only one device logged in at a time. If you log in from this device, the other device will be logged out. Do you want to proceed?"  But, this time, choose "No" and the response page displayed a conflicting dynamic IP address, which is different from the dynmamic IP address assigned to the laptop. which I applied the firmware upgrade from.  On a whim, I turned off my WIFI connection on my cell phone.  I tried to ping the new, conflicting IP address assigned and the request timed out. I then tried to connect to the administration page using the default gateway IP address, SUCCESS.

 

Bottom line, check what other device may be connected, which I was able to determine by choosing "No" to the Do you want to proceed?

Model: WNDR4000|N750 Wireless Dual Band Gigabit Router|EOL
Message 4 of 10
William10a
Master

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

Have you tried clearing the catch of the internet browser you are using on the computer?

Message 5 of 10
Aaron407
Tutor

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

I fought with this same issue today after recently updating the firmware. It would let me enter the login credentials, then tell me that another device was already logged in. If I clicked on "yes" to kick the other device off, it would refuse the connection. Power cycling it didn't help and the problem continued, but I did eventually get it working.

 

After power cycling and entering the login credentials, I clicked on "no" when prompted to log out the other device, which then showed me the IP address that was apparently logged into it. I went to that device and was able to successfully log in, then log out. After that, I could successfully log in on the computer that I was originally attempting to use. It seems like it locks onto the last login device if you don't properly log out, and even a power cycle won't help. Since you can't force the log out as it states, it's certainly an issue with the firmware update, but fully logging out seems to work now. Hopefully it'll work for you as well.

Message 6 of 10
colemickens
Initiate

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

This is unacceptable. I'm not logged in from any other device. Netgear shipped an update that causes their own Web UI to crash? What does that say about the security of this product? This is simply unacceptable. My router is now useless because I can't edit my firewall settings at all.

Message 7 of 10
ElaineM
NETGEAR Employee Retired

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

@colemickens Did you try clearing your cache and browsing history? 

How about resetting the router? 

 

Message 8 of 10
colemickens
Initiate

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

I'm experiencing the exact symptoms in this thread.

 

So yes, I've already rebooted/reset the router. It's the only way to get the Web UI to come back up after it crashes.

Clearing browser history doesn't do anything. This is an issue with the router, where it stupidly tries to track the "managing client" by IP address.

 

Well guess what, after it applied the update, it lost the DHCP client cache, re-issued a new IP address to my laptop... and now I can't "logout" from there. And the "force logout" function is *exactly what is crashing the Web UI in the router*.

 

Like I said, unacceptable and amateurish, making me question the fundamental security of this product.

Message 9 of 10
markman
Aspirant

Re: WNDR4000 - Blocking Admin Access After Latest Security Update

(Sorry for the late response)

 

Here is what seems to be happening:

 

After updating the firmware, the TCP/IP address of the admistrative device that was used to log into the router is somehow being permanently cached. So... when you change the SSID/security/admin password/etc immediately after the upgrade, the box will reboot itself.  When that happens, you MUST have the same IP address in order to log back in - rebooting the router again does not clear that cached IP address.  The prior solution of clicking "No" on the popup window to find out what IP address to use applies - make sure you use that adress.

 

Now, once you have logged in AND out (I think) that protective mechanism works "properly" - it still caches the previous IP adress with no apparent timeout, but powering down the router will clear that cache.  

 

I think this is still a little wonky (I am also experiencing some lag/buffering) but at least I can administer the router (still may be time for a replacement).

 

 

Message 10 of 10
Top Contributors
Discussion stats
  • 9 replies
  • 8354 views
  • 4 kudos
  • 7 in conversation
Announcements

Orbi WiFi 7