Orbi WiFi 7 RBE973
Reply

R8500 security alert email.

RAKRA
Follower

R8500 security alert email.

Is the recent email I received legit?  Subject line "Web GUI Password Recovery and Exposure Security Vulnerability"

Model: R8500|Nighthawk X8 Tri-Band AC5300 WiFi Router
Message 1 of 11

Accepted Solutions
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

Hi @RAKRA

 

Welcome to the community!

 

Yes, it is legit.

Here's the link in the community regarding the announcement.

View solution in original post

Message 2 of 11

All Replies
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

Hi @RAKRA

 

Welcome to the community!

 

Yes, it is legit.

Here's the link in the community regarding the announcement.

Message 2 of 11
VirginiaUser
Tutor

Re: R800 security alert email.

The announcement is NOT user friendly for people who are not tech experts. 

It makes NO sense to us.   Thus, it raises questions about whether it is a scam.

 

What the heck is a web GUI password?

 

Netgear should NOT use techy terms and abbreviations when informing customers about problems.

 

I have no idea what this is.  I don't understand the announcement.   I have no idea about the consequences.   That's how bad the message sent to customers is.  Thus, most people like me will likely ignore it.

Message 3 of 11
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

@VirginiaUser Thank you for your valuable feedback. Let me forward this to our management team.

Message 4 of 11
rkassnel
Initiate

Re: R800 security alert email.

Yes please. I agree completely with VirginiaUser. I have no clue how to change my router password (Netgear Genie logs me in automatically every time I launch it), nor have I found any step-by-step instructions on how to disable romote access. I saw a step-by-step answer somewhere on your site for changing the router password, but the Genie screenshots in that answer look nothing like my Genie interface. I see no "Advanced" tab under Router Settings. Grrr.

Message 5 of 11
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

@rkassnel What's the exact model number of your NETGEAR device?

Message 6 of 11
rkassnel
Initiate

Re: R800 security alert email.

R4500

Message 7 of 11
VirginiaUser
Tutor

Re: R800 security alert email.

Why did I receive the netgear message if my router is model R6200?


Despite my earlier message, netgear still has not explained what the underlying problem is or why it matters.   This is extremely important, but still no info from netgear.

 

Is someone trying to hack into routers?

If so, what does that even mean for users?
What can such people get by doing so?

Message 8 of 11
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

@rkassnel On page 81 of the manual, it shows how to enable Password Recovery while on page 101 shows how to disable Remote Management.

Let me just add, your router is not included in the affected list.

 

@VirginiaUser There are a lot of malicious users all over the internet and the provided steps helps prevent an access to your important files and details stored in your network.

Message 9 of 11
VirginiaUser
Tutor

Re: R800 security alert email.

This is NOT an adequate response.   It is no response at all.

 

Please answer the questions I already posed.

 

What is the problem?

What is wrong with the router?

What can a hacker do with the router to get to user computers?

 

And you have not even come close to addressing my first post.
What the heck is GUI?

What do you mean by password recovery?

 

How does any of this relate to your router?

 

This may be obvious stuff to you people who made the router but it is not obvious or even remotely clear to consumers who merely plug in a router in order to use the internet wirelessly.

 

Also, the email I received references R800.  What the heck is that?

Is that even a router model number?

Message 10 of 11
ElaineM
NETGEAR Employee Retired

Re: R800 security alert email.

The correct model number that is affected by the vulnerability is R8000. Can you post a screenshot where it says R800?


GUI is Graphical User Interface which is a term we use to refer the settings page of the router.

Here's an article on how to get into the admin page of the router.

Password recovery is a feature of the router where you can recover the password in any case you have forgotten it by just answering several questions.


Regarding all other concerns, kindly contact our security team at security@netgear.com


For reference, here are some articles that refers to the vulnerability:

 

Web GUI Password Recovery and Exposure Security Vulnerability

NETGEAR Product Security Advisory

Message 11 of 11
Top Contributors
Discussion stats
  • 10 replies
  • 6330 views
  • 5 kudos
  • 4 in conversation
Announcements

Orbi WiFi 7