NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Security
1979 TopicsFeature request: provide true network segmentation for guest wifi
It would be great if you could improve the guest wifi capabilities, at least giving the option of complete network segmentation for guest networks on your routers. Visitors, and untrusted devices (e.g., IoT devices) should be able to connect to a separate SSID, on a (separate) VLAN (or other logical segmentation), so that guest devices can't discover, communicate with, or sniff traffic from, devices on the trusted SSID, except as explicitly permitted through user-created rules. Ideally, VLAN management should also extend to the ethernet ports on the router and satellites, so that wired devices can also be segmented out to the untrusted VLAN (e.g., wired IoT devices).8.1KViews25likes4CommentsNighthawk M5 MR5100-1Z1MES useless In Middle East
Good day NETGEAR COMMUNITY ! , First of all, We are in big trouble because a lot of people In Middle East They didn't get the new update : Model: MR5100-1Z1MES Firmware Version : NTGX55_12.04.12.01 GUI Version: MR5100-1Z1MES_04.02.197.00 HW Version: 1.1 _________________________________________________________________ Most of people stuck on version : 10.12.13.0 & 10.28.02.00 Which is very old version and you cannot change band option's from the router ! You shall to change It from 192.168.1.1 ! Also, when you tried to check for updates It's give you UP TO DATE ! _________________________________________________________________ Is it difficult for a large and leading company in the field of routers like Netgear to Push an OTA update 12.04.12.01 to all owners of the MR5100-1Z1MES model ? By the way .... The vendor not cooperate at all In Middle EastSolvedGS108Ev3 Cannot set VLAN for management interface
I just purchased a GS108Ev3 because I needed some simple VLAN segregation for a small group of machines "down the hall" from my core networking equipment. The switch works great, though there is one key feature I believe to be missing: The IP address of the switch can be staticly defined, but there is no way to configure the VLAN the switch's management interface resides on. With my ProSafe Smart switches that I'm currently using, this is definetly possible: GS724T Management Interface: On the other hand, the GS108E clearly lacks this functionality: GS108E Mangement Interface: (Same basic form is visable in the WebUI; no VLAN setting though!) Setting the IP address is great... but I need to keep all of the management for my switches on a seperate VLAN for security purposes. Is this a feature that could possibly be added with a future firmware revision? I know the GS108E is a very entry-level switch, but since the switch supports VLANs and managing them on a per-port bases (and trunking), allowing administrators to set the VLAN for the management interface is really an important feature!Solved39KViews9likes13CommentsSupport HTTPS oin GS1xxE web Managet Switches
Please consider using HTTPS for the web management of the GS1xxE line of switches. Especially the smaller models need a secure way to configure them as there are no real replacements for in-field deployments outside special technical rooms where is no room to fit an entire rack into... As the current state of security of many of the embedded or IoT thingis is sub-optimal it is crucial to prevent login credential sniffing via other pOwnd network devices within the same subnet. Thanks, Stefan Seide12KViews8likes1CommentR7000 Vulnerability Note VU#582384
It has been reported on various outlets that there is a vulnerability with the R7000 and R6400 routers. Please see https://www.kb.cert.org/vuls/id/582384 . The advisor reads "Exploiting this vulnerability is trivial. Users who have the option of doing so should strongly consider discontinuing use of affected devices until a fix is made available." This is NOT a practical solution for me or many others. I can't find anything on the Netgear website about this issue and how they intend to resolve it. Can anyone advise as to the status of this problem and share any information and advise ? Thanks JMKSolved18KViews8likes45CommentsNETGEAR Routers and CVE-2016-582384 security vulnerability
I am a bit concerned about this recent article: http://www.zdnet.com/article/two-netgear-routers-are-vulnerable-to-trivial-to-remote-hack/ https://www.kb.cert.org/vuls/id/582384 Details: Overview Netgear R7000 and R6400 routers and possibly other models are vulnerable to arbitrary command injection. Description CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') Netgear R7000, firmware version 1.0.7.2_1.1.93 and possibly earlier, and R6400, firmware version 1.0.1.6_1.0.4 and possibly earlier, contain an arbitrary command injection vulnerability. By convincing a user to visit a specially crafted web site, a remote attacker may execute arbitrary commands with root privileges on affected routers. A LAN-based attacker may do the same by issuing a direct request, e.g. by visiting: http:///cgi-bin/;COMMAND An exploit leveraging this vulnerability has been publicly disclosed. Impact By convincing a user to visit a specially crafted web site, a remote attacker may execute arbitrary commands with root privileges on affected routers. Solution The CERT/CC is currently unaware of a practical solution to this problem and recommends the following workaround. Discontinue use Exploiting this vulnerability is trivial. Users who have the option of doing so should strongly consider discontinuing use of affected devices until a fix is made available. --------------------------- Can someone from NetGear address this issue? I am running one level behind on my firmware, because I liked the fact that my router could double as my ARLO base station. However, reading this warning from CERT is causing me to be concerned. This router was not cheap, and I have had it for less than a year. If I have to get rid of it, becaue the issue cannot be resolved, then I would like some kind of compensation or trade in value. Regards.Solved28KViews8likes233CommentsNetgear R7000 and OpenVPN for Android App
Hi, since last OpenVPN for Android App update (v.0.6.73) downloadable at the following link: https://play.google.com/store/apps/details?id=de.blinkt.openvpn OpenSSL version was upgraded to 1.1 and I cannot connect to my R7000 Router from Outside anymore, because for security reasons OpenSSL v.1.1 doesn't accept MD5 certificates because have a weak signature. May Netgear upgrade R7000 firmware to create OpenVPN SHA256 certs instead MD5, below the OpenVPN's FAQ with explanations: http://ics-openvpn.blinkt.de/FAQ.html#weakmd_title It's a security enhancement that may be helpful to all community that have this fantastic Router. Router Firmware: 1.0.7.12 Smartphone Model: LG Google Nexus 5X v.7.1.2 with June 5th 2017 patches. Regards.Solved42KViews7likes138Commentsnew idea for security for all modem and raouters
update your security new inteligent firewall and monitor so you can see what is passing over the firewall and what is bloking in real time like attack ,junk,virus,scrips attack,dos,ddos,bots,malware,exploit bloking,portscan,domain infected,dns,ip ,devices ect IP spoofing attack dns poisoning attack arp poisoning attack tcp and upd port scaning attack protocol SMB attack protocol RPC attack protocol RDP attack Man in the middle attack Session hijacking Server spoofing Ping broadcast Ping of death Smurf Teardrop syn flood brute force ect so you can you can block any coonection with servers ,dns,ips,uknow device conected to the firewall,like hakers ,ect make allow rule or deny so you can deside what block or not or the same firewall tell you that is safe or not makenew ids protection and new gen intrution prevention ( fix all false and positive attack ) network monitor so you can block or deny network too of devices see all conection conected and full speed running so you can see what speed is running like 50mbs or more ect see ping and pakage lost and signal stable and see lag spike ect like for example xboxone or ps4 make new inteligent anti exploit protection protect from any exploit and zero exploit over the network or any new atack tech make memory protection ,protect from any attaack from memory modem or raouter make ready nas and share protection make usb protection make new anti dos or any attack wirless make anti jamming wirless for 2.4ghz and 5ghz prevent wirless drops and secure voice ect make a new turbo nat for gaming make new turbo firewall fix the dos and portscan and security make modem slow playing online games speed up the setting that dont affect gaming on any security setting scrip protection make anti bypass firewall make new unpnp protection make hhtps login and secure make dns protection make new gen turbo qos gaming set upload and download speed make a new modem or router speed test fix put the same ip on portward dont work fix that like example fist ip 192.168.10 for xbox second ip 192.168.9 for xbox in case the ip change dont let you fix that dont support mutiple ip make a new disnotic mode test security or vulneravility settings you have make new smart ip conflic fix make new uknow change have been made incase of hakers and what setting was change make turbo chanels for download and upload make to change upload and download frecuency make a new gen modem software for all make super fast software fix always disconection on modems for gaming make super fast cpu 4 core 2.20ghz or higth turbo for modem ect make gaming modem make smart porforward ports nope error and security make support ipv6 for portfoward and all settings like dns ip ect make to disable ready share for the modem add protection for printer security cold be vulnerable and easy for hakers make anti remote bypass and security wps security ect just helping30KViews7likes2Comments