Orbi WiFi 7 RBE973
Reply

Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9

ikonuk
Guide

Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9

My NETGEAR router has been reporting vulnerabilities with the latest firmware (6.10.9) as it can be seen from the following screen capture. Is NETGEAR going to do anything about it?

 

I. Konuk

 

ReadyNasOS_vulnerability_by_Nighthawk_08152023.jpg

Message 1 of 5
schumaku
Guru

Re: Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9

Lack of any insight or details about the report - how useless information for the average user: We can just guess this security scan want to tell us that http access to the ReadyNAS admin Web is insecure (indeed, ...). Needless to say, at the current EoL status of ReadyNAS, it's more than unlikely this nice, user-friendly default will be removed.

Message 2 of 5
StephenB
Guru

Re: Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9

I agree with @schumaku that the lack of detail in the report makes it not actionable.

 

What services do you have enabled on the NAS?

Do you have any ports forwarded to the NAS in the router?

 

Is your NAS set up to allow anonymous access to shares?

Another possibility is that the NAS is allowing SMB 1 connections - which you could disable is smbplus is installed.

Message 3 of 5
ikonuk
Guide

Re: Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9

Thank you @schumaku and @StephenB.

 

I did have SMB and iTunes enabled for some reason. I disabled it. I will post the outcome.

 

No ports are forwarded.

Message 4 of 5
schumaku
Guru

Re: Nighthawk software reports vulnerabilities with ReadyNAS Firmware 6.10.9


@ikonuk wrote:

I did have SMB and iTunes enabled for some reason. I disabled it. I will post the outcome.


Curious how one does use a NAS (and for what purpose) without the SMB protocol? Could be SMB 1.0 enabled as @StephenB mentioned. The iTunes Service is not security relevant - very different from the default http access ...

Message 5 of 5
Top Contributors
Discussion stats
  • 4 replies
  • 1109 views
  • 0 kudos
  • 3 in conversation
Announcements