WiFi Monitor is showing the network as WPS enabled: so it seems it is susceptible to the WPS hacks out there. There is also no visible way to disable WPS within the Orbi Login controls.
The Wikipedia article on WPS gives the impession that WPS is a mandatory WiFi feature.
https://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup
The WPS \"button\" method has proved useful for connecting a number of devices.
When I look at Orbi parameters, there are several that have \"wps\", including:
wps_lock_down=0
WPS_type=0
wps_pin_attack_check=1
I guess a person could telnet into the Orbi and set wps_lock_down to some other value (\"1\"?)
I would also guess that turning on Access Control and checking \"Do not allow new devices to connect\" might block WPS connections.
If it will block devices that present the correct WiFi SSID/password, it would seem reasonable to block new devices which use WPS.
That should be easy to verify.
","body@stringLength":"1422","rawBody":"
wrote: WiFi Monitor is showing the network as WPS enabled: so it seems it is susceptible to the WPS hacks out there. There is also no visible way to disable WPS within the Orbi Login controls.
The Wikipedia article on WPS gives the impession that WPS is a mandatory WiFi feature.
https://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup
The WPS \"button\" method has proved useful for connecting a number of devices.
When I look at Orbi parameters, there are several that have \"wps\", including:
wps_lock_down=0
WPS_type=0
wps_pin_attack_check=1
I guess a person could telnet into the Orbi and set wps_lock_down to some other value (\"1\"?)
I would also guess that turning on Access Control and checking \"Do not allow new devices to connect\" might block WPS connections.
If it will block devices that present the correct WiFi SSID/password, it would seem reasonable to block new devices which use WPS.
That should be easy to verify.
","author":{"__ref":"User:user:380593"},"isEscalated":null,"postTime":"2021-01-28T08:29:32.098-08:00","solution":false,"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"repliesCount":9},"Revision:revision:2047657_1":{"__typename":"Revision","id":"revision:2047657_1","lastEditTime":"2021-01-28T11:19:05.647-08:00"},"QueryVariables:ReplyList:message:2047657:1":{"__typename":"QueryVariables","id":"ReplyList:message:2047657:1","value":{"id":"message:2047657","first":10,"sorts":{"postTime":{"direction":"ASC"}},"repliesFirst":3,"repliesFirstDepthThree":1,"repliesSorts":{"postTime":{"direction":"ASC"}},"useAvatar":true,"useAuthorLogin":true,"useAuthorRank":true,"useBody":true,"useKudosCount":true,"useTimeToRead":false,"useMedia":false,"useReadOnlyIcon":false,"useRepliesCount":true,"useSearchSnippet":false,"useAcceptedSolutionButton":true,"useSolvedBadge":false,"useAttachments":false,"attachmentsFirst":5,"useTags":false,"useNodeAncestors":false,"useUserHoverCard":false,"useNodeHoverCard":false,"useModerationStatus":true,"usePreviewSubjectModal":false,"useMessageStatus":true}},"ROOT_MUTATION":{"__typename":"Mutation"},"CachedAsset:text:en_US-components/customComponent/CustomComponent-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-components/customComponent/CustomComponent-1749758811689","value":{"errorMessage":"Error rendering component id: {customComponentId}","bannerTitle":"Video provider requires cookies to play the video. Accept to continue or {url} it directly on the provider's site.","buttonTitle":"Accept","urlText":"watch"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/users/UserAvatar-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/users/UserAvatar-1749758811689","value":{"altText":"{login}'s avatar","altTextGeneric":"User's avatar"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/ranks/UserRankLabel-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/ranks/UserRankLabel-1749758811689","value":{"altTitle":"Icon for {rankName} rank"},"localOverride":false},"CachedAsset:text:en_US-components/common/ExternalLinkWarningModal-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-components/common/ExternalLinkWarningModal-1749758811689","value":{"title":"Leaving the Community","description":"You're about to leave this site and navigate to an external domain. Are you sure you want to continue?","action.submit":"Continue","action.cancel":"Go Back"},"localOverride":false},"CachedAsset:text:en_US-components/messages/AcceptedSolutionButton-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-components/messages/AcceptedSolutionButton-1749758811689","value":{"accept":"Mark as Solution","accepted":"Marked as Solution","errorHeader":"Error!","errorAdd":"There was an error marking as solution.","errorRemove":"There was an error unmarking as solution.","solved":"Solved","topicAlreadySolvedErrorTitle":"Solution Already Exists","topicAlreadySolvedErrorDesc":"Refresh the browser to view the existing solution"},"localOverride":false},"CachedAsset:text:en_US-components/messages/ThreadedReplyList-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-components/messages/ThreadedReplyList-1749758811689","value":{"title":"{count, plural, one{# Reply} other{# Replies}}","title@board:BLOG":"{count, plural, one{# Comment} other{# Comments}}","title@board:TKB":"{count, plural, one{# Comment} other{# Comments}}","title@board:IDEA":"{count, plural, one{# Comment} other{# Comments}}","title@board:OCCASION":"{count, plural, one{# Comment} other{# Comments}}","noRepliesTitle":"No Replies","noRepliesTitle@board:BLOG":"No Comments","noRepliesTitle@board:TKB":"No Comments","noRepliesTitle@board:IDEA":"No Comments","noRepliesTitle@board:OCCASION":"No Comments","noRepliesDescription":"Be the first to reply","noRepliesDescription@board:BLOG":"Be the first to comment","noRepliesDescription@board:TKB":"Be the first to comment","noRepliesDescription@board:IDEA":"Be the first to comment","noRepliesDescription@board:OCCASION":"Be the first to comment","messageReadOnlyAlert:BLOG":"Comments have been turned off for this post","messageReadOnlyAlert:TKB":"Comments have been turned off for this article","messageReadOnlyAlert:IDEA":"Comments have been turned off for this idea","messageReadOnlyAlert:FORUM":"Replies have been turned off for this discussion","messageReadOnlyAlert:OCCASION":"Comments have been turned off for this event"},"localOverride":false},"User:user:74881":{"__typename":"User","id":"user:74881","uid":74881,"login":"FURRYe38","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2010-04-14T14:22:21.000-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://community.netgear.com/t5/s/ejquo23388/images/dS03NDg4MS0zMzk1OWk0ODAwMTQ0QkQ4QkRGMDA5"},"rank":{"__ref":"Rank:rank:57"},"entityType":"USER","eventPath":"community:ejquo23388/user:74881"},"ModerationData:moderation_data:2047661":{"__typename":"ModerationData","id":"moderation_data:2047661","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"ForumReplyMessage:message:2047661":{"__typename":"ForumReplyMessage","uid":2047661,"id":"message:2047661","entityType":"FORUM_REPLY","eventPath":"category:home-orbi/category:home-networking/category:English/community:ejquo23388board:Orbi/message:2047325/message:2047661","revisionNum":1,"author":{"__ref":"User:user:74881"},"readOnly":false,"repliesCount":7,"depth":3,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:Orbi"},"parent":{"__ref":"ForumReplyMessage:message:2047657"},"conversation":{"__ref":"Conversation:conversation:2047325"},"subject":"Re: WPS is ON all the time, and can't be disabled","moderationData":{"__ref":"ModerationData:moderation_data:2047661"},"body":"
I might presume that NG may employ some form of there own WPS handling and syncing that is proprietary on Orbi or NGs MESH systems which only is behind the scenes and is apart of there core non GPL code. Something that can't be access or changed by access from telnet.
","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"203","kudosSumWeight":0,"postTime":"2021-01-28T11:23:35.517-08:00","lastPublishTime":"2021-01-28T11:23:35.517-08:00","metrics":{"__typename":"MessageMetrics","views":6715},"visibilityScope":"PUBLIC","placeholder":false,"showMoveIndicator":false,"originalMessageForPlaceholder":null,"isEscalated":null,"solution":false,"replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[{"__typename":"MessageEdge","cursor":"MjUuNHwyLjF8aXwzfDM5OjF8aW50LDIwNDc2NjgsMjA0NzY2OA","node":{"__ref":"ForumReplyMessage:message:2047668"}}]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"ModerationData:moderation_data:2047668":{"__typename":"ModerationData","id":"moderation_data:2047668","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"ForumReplyMessage:message:2047668":{"__typename":"ForumReplyMessage","uid":2047668,"id":"message:2047668","entityType":"FORUM_REPLY","eventPath":"category:home-orbi/category:home-networking/category:English/community:ejquo23388board:Orbi/message:2047325/message:2047668","revisionNum":3,"author":{"__ref":"User:user:700345"},"readOnly":false,"repliesCount":6,"depth":4,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Forum:board:Orbi"},"parent":{"__ref":"ForumReplyMessage:message:2047661"},"conversation":{"__ref":"Conversation:conversation:2047325"},"subject":"Re: WPS is ON all the time, and can't be disabled","moderationData":{"__ref":"ModerationData:moderation_data:2047668"},"body":"By looking at all of the channels in use by the Orbi, there are several back channels without SSID open, I'm going to guess that the WPS is used to create and open those back channels. The only option to create a new PIN is to use the Backhaul \"Generate New Password\" ... This new PIN is then stored for when the router/slave reboot or power cycle.
Bottom line, there is a PIN to hack, and it looks like it is an inherent system capability/vulnerability that can't be disabled.
Backhaul Password |
Orbi can generate a new hidden password to improve security for its backhaul connection. |
WARNING: Generating a new password might cause the Orbi satellite to lose connection from the Orbi router. To reconnect, use the SYNC button |
Again, I might presume that NG may employ some form of there own WPS handling and syncing that is proprietary on Orbi or NGs MESH systems which only is behind the scenes and is apart of there core non GPL code.
If you feel that his is an issue. Please contact NG support and advise them of your concerns. There would not nothing we can do here in the forums to effect a change.
","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"208","kudosSumWeight":0,"repliesCount":5,"postTime":"2021-01-28T12:13:42.334-08:00","lastPublishTime":"2021-01-28T12:13:42.334-08:00","metrics":{"__typename":"MessageMetrics","views":6680},"visibilityScope":"PUBLIC","placeholder":false,"showMoveIndicator":false,"originalMessageForPlaceholder":null,"isEscalated":null,"solution":false,"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"CachedAsset:text:en_US-shared/client/components/common/Pager/PagerLoadMore-1749758811689":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/Pager/PagerLoadMore-1749758811689","value":{"loadMore":"Show More"},"localOverride":false}}}},"page":"/forums/ForumMessagePage/ForumMessagePage","query":{"boardId":"Orbi","messageSubject":"wps-is-on-all-the-time-and-cant-be-disabled","messageId":"2047325","replyId":"2047657"},"buildId":"3XH0qYWYCnEYycuN5W4S8","runtimeConfig":{"buildInformationVisible":false,"logLevelApp":"info","appLogLevelOverrides":"TenancyMiddleware=TRACE,OriginHelper=TRACE","logLevelMetrics":"info","surveysEnabled":true,"openTelemetry":{"clientEnabled":false,"configName":"netgear","serviceVersion":"25.4.0","universe":"prod","collector":"http://localhost:4318","logLevel":"error","routeChangeAllowedTime":"5000","headers":"","enableDiagnostic":"false","maxAttributeValueLength":"4095"},"apolloDevToolsEnabled":false,"quiltLazyLoadThreshold":"3"},"isFallback":false,"isExperimentalCompile":false,"dynamicIds":["components_seo_QAPageSchema","components_community_Navbar_NavbarWidget","components_community_Breadcrumb_BreadcrumbWidget","components_customComponent_CustomComponent","components_messages_TopicWithThreadedReplyListWidget","components_languages_LanguagePicker","components_messages_MessageView_MessageViewStandard","components_external_components_ExternalComponent","components_messages_EscalatedMessageBanner","components_customComponent_CustomComponentContent_HtmlContent","components_customComponent_CustomComponentContent_CustomComponentScripts","shared_client_components_common_List_UnstyledList","components_messages_MessageView","shared_client_components_common_Pager_PagerLoadMore"],"appGip":true,"scriptLoader":[]}