Netgear R7000 and R6400 routers are vulnerable to arbitrary command injection

Discussion in 'other security issues & news' started by ronjor, Dec 9, 2016.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    Original Release date: 09 Dec 2016 | Last revised: 09 Dec 2016
     
  2. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    :eek: I wonder if my D6400 is vulnerable too?
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    I looked here and didn't see any alerts. You can sign up for their security advisory newsletter.
     
  4. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Thanks, Ron.
     
  5. jdd58

    jdd58 Registered Member

    Joined:
    Jan 30, 2008
    Posts:
    556
    Location:
    Sonoran Desert
    I've been considering flashing mine to dd-wrt. If that would mitigate the vulnerability now would be a good time I suppose.
     
  6. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    CERT edited this alert adding:
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    Security Advisory for VU 582384
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    I'm using an alternative for the time being. I had not long ago updated the firmware of my D6400 which "Added few security enhancements".
     
  9. Consumer modems/routers are garbage. Even the $300+ models are awful security wise.
     
  10. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
  11. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    NETGEAR modem-router line "D" seems not affected by the problem.
     
  12. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Cool! Thanks for the info. :thumb:
     
  13. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Well, it is now.

    http://kb.netgear.com/000036386/CVE-2016-582384

    • R6250*
    • R6400*
    • R6700*
    • R6900*
    • R7000*
    • R7100LG*
    • R7300DST*
    • R7900*
    • R8000*
    • D6220*
    • D6400*
    Back to my other modem router. No, I'll install the beta firmware.
     
  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Hi @fax,

    I read your post before it was deleted and I agree that its great that they provided a beta firmware so quickly, and hopefully a stable version soon.

    I don't think Netgear list vulnerable versions until they have provided a fix so there may be more to come yet.
     
  15. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Could be... the list seems stable now but indeed you never know.
     
  16. jdd58

    jdd58 Registered Member

    Joined:
    Jan 30, 2008
    Posts:
    556
    Location:
    Sonoran Desert
    Production firmware fix is available now for the R6400, R7000, and R8000.

    Others are still beta at this time.
     
  17. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    I have upgraded a R6400 and a R7000 to the new production firmware releases for both these Netgear routers. Normal operation continues. :)
     
  18. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    All products now have production firmware fixes available.

    http://kb.netgear.com/000036386/CVE-2016-582384

    For my D6400 the new firmware is the same version number as the beta firmware, but I'll install it just in case there's a difference.
     
  20. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    A reminder for anyone with a NETGEAR router to manually check for firmware updates. I logged into my D6400 and checked but it said there were no updates available, but checking their site showed a new version that fixes a security issue.

    https://kb.netgear.com/000038417/D6400-Firmware-Version-1-0-0-58

    New Features and Enhancements:
    • Security fix and enhancement.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.