NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Security
526 TopicsLetter of Volatility
Hi all, I need a letter of volatility for the following products: Netgear GS108 Netgear GS308 Netgear GS108PP Netgear GS308PP Netgear GS308EP Netgear GS310TPv2 I have support case 49769612, but was unable to get it in chat or get someone on the phone. Thank you.47Views0likes2CommentsWAX210 Firmware 1.1.0.34 Bug – SSID Password Complexity Incorrectly Enforced
Hi everyone — I’m seeing what looks like a firmware regression on the WAX210 after updating to v1.1.0.34, and I want to report it in case others are affected. After updating, the AP now refuses to save any configuration changes (even unrelated ones like just renaming the Access Point). The UI throws this error: SSID1: SSID passphrase length must be between 8 and 63 characters, and contain at least one uppercase letter, one lowercase letter, one number, and one special symbol. This happens even when the SSID password is not edited at all. The AP loads the existing (valid) WPA2/WPA3 passphrase and flags it as invalid due to a complexity requirement that didn’t exist before. This appears to be the AP Login Password complexity policy being mistakenly applied to SSID passphrases, which contradicts the official manual. SSID passwords for WPA2/WPA3 should only require 8–63 characters. Reproduction Steps Update WAX210 to firmware 1.1.0.34 Log into the web interface Make any change (example: AP Name only) Click Apply The SSID password complexity error appears, even though SSID settings were untouched Impact. The AP cannot accept any configuration changes unless the SSID password is replaced with a much more complex passphrase. This forces a complete re-key of all connected devices. Expected Behavior Per the WAX210 User Manual, SSID passphrases should be valid with: 8 to 63 characters No requirements for uppercase/lowercase/digits/symbols Those rules worked correctly in previous firmware versions. Current Workaround Rolling back to firmware 1.1.0.25 or 1.1.0.20 fully resolves the issue. Request Can Netgear please confirm whether this is a regression in 1.1.0.34 and escalate to the firmware engineering team? This issue effectively prevents configuration of the device. I can provide: Screenshots of the error dialog A configuration backup A short video showing the issue Exact hardware revision and serial if needed Thanks in advance.1.1KViews4likes21CommentsOTP Security for Browser Admin Accounts
I use a NetGate router with one port dedicated to the WAX610. I do that so i can impose firewall rules to limit mobile access to the rest of our LAN. Does anyone know if NetGear plans to add MFA to the browser based admin & user accounts of its access points? Please don't send me to Insight. I want to reduce my attack surface, not increase it.92Views0likes4CommentsWAX610 – 802.1X Supplicant on Wired Uplink Port – Feature Availability
Hello NETGEAR Support Team, I am currently deploying a network infrastructure using several WAX610/WAX620 access points (firmware up to date) combined with a MS510TXPP managed switch. As part of my security architecture, I would like to enable 802.1X port authentication on the switch ports connected to the access points, in order to prevent unauthorized access in the event an AP is physically removed and replaced by a rogue device. This requires the WAX610 to act as an 802.1X supplicant on its wired uplink/LAN port — independently from the 802.1X authenticator role it already plays for wireless clients via RADIUS. After reviewing the WAX610 user manual thoroughly, I could not find any mention of this capability on the wired port. My questions are: Does the WAX610 currently support 802.1X supplicant functionality on its wired uplink port? If not, is this feature on the roadmap for a future firmware release? This is a fairly standard enterprise security requirement, and I believe many customers deploying WAX610 in environments where physical security of the AP cannot be fully guaranteed would benefit from it. Thank you for your time and assistance. Best regards60Views0likes1CommentAdvanced 802.1Q VLAN Doesn't Block Untagged Traffic?
I think the answer might be obvious. Lower-end Netgear switches are not managed using VLAN traffic, so they allow all untagged traffic to pass through. Is this correct? For example, a port is configured with VLAN ID 10 for untagged traffic and its PVID is 10. It will tag the traffic correctly and all the traffic will go to the correct subnet. However, if I manually configure my IP, I can access any other device on the link that is not VLAN aware. This could be another Netgear switch or a MoCA device. My configuration: Devices: GS308EP GS305ERequest: List of Products That Perform Cryptographic Key Provisioning
We are reviewing your networking products for internal compliance purposes. Could you please confirm which of your hardware-based products (e.g., switches, routers, relays, gateways) include any of the following cryptographic functions: Provisioning or distribution of encryption keys to other devices Acting as a MACsec Key Server (e.g., providing CAKs/SAKs to peers via MKA) Providing IPsec/IKEv2 key exchange for other systems Embedded EAP/PKI certificate provisioning or CA functions Managing network-wide encryption policies or certificate trust for other devices We are not asking about encryption used only for login/authentication (e.g., HTTPS, SNMPv3, 802.1X), or encryption used solely for the unit’s own interfaces. This request is limited to cases where the product provides or manages encryption on behalf of other devices. If possible, please provide a list or matrix identifying which models include any of the above features. Any documentation that describes these capabilities would also be appreciated. Thank you for your support.164Views0likes0Comments