Home
 » ISP News » 
Sponsored Links

UPDATE Hackers Start to Exploit New NETGEAR Router Security Flaws

Saturday, Oct 10th, 2015 (8:22 am) - Score 3,906

Consumers who own any one of several NETGEAR broadband router models (JNR1010v2, JNR3000, JWNR2000v5, JWNR2010v5, N300, R3250, WNR2020, WNR614, WNR618) could be vulnerable to two new exploits that may allow a remote attacker to gain full control of your device.

Apparently these exploits, which were first discovered during the summer and have only recently been published online (here and here), only work over the Internet if the router has Wide Area Network (WAN) Administration enabled (this is not normally switched on by default). Otherwise the hacker would need to be physically near to your network.

Advertisement

A successful attack would grant the hacker unauthenticated root access, which could allow them to do various things, such as snooping on your network traffic by changing your DNS settings so that any website requests and inputs run through compromised servers.

A related report on the BBC shows that such attacks are already happening, although it’s not yet a huge problem because not everybody will have their device open to remote access. But some hackers do drive around looking for vulnerable networks to exploit.

NETGEAR are clearly aware of the problem and taking it seriously, in fact they’ve already developed a firmware fix, but they have yet to release an update for all of the affected routers. Device manufacturers can be lazy and tend to stop providing support for their routers after a few years, even though the kit may remain in use for a lot longer.

UPDATE 13th October 2015

Advertisement

The following is a new statement from NETGEAR, which yesterday released a new firmware fix for the stated router models.

A NETGEAR Spokesperson told ISPreview.co.uk:

NETGEAR takes customer security very seriously. A firmware update has been released to address the issue: http://kb.netgear.com/app/answers/detail/a_id/29959. NETGEAR is proactively notifying registered users via email, plus customers can find the new firmware by checking the firmware page, desktop, and mobile Genie app.

NETGEAR encourages its customers to ensure WiFi security is turned on and that remote access functionality is turned off (both default settings in NETGEAR’s routers and gateways). NETGEAR also advises customers to change the default password for the router to prevent unauthorised devices from accessing your network.”

Tags:
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and .
Search ISP News
Search ISP Listings
Search ISP Reviews

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
100Mbps
Gift: None
Vodafone UK ISP Logo
Vodafone £22.00
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £23.99
264Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £24.99
145Mbps
Gift: £145 Reward Card
Youfibre UK ISP Logo
Youfibre £24.99
200Mbps
Gift: None
Large Availability | View All
Promotion
Cheap Unlimited Mobile SIMs
iD Mobile UK ISP Logo
iD Mobile £16.00
Contract: 24 Months
Data: Unlimited
Talkmobile UK ISP Logo
Talkmobile £16.95
Contract: 1 Month
Data: Unlimited
ASDA Mobile UK ISP Logo
ASDA Mobile £19.00
Contract: 24 Months
Data: Unlimited
Smarty UK ISP Logo
Smarty £20.00
Contract: 1 Month
Data: Unlimited
O2 UK ISP Logo
O2 £21.24
Contract: 24 Months
Data: Unlimited
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
Community Fibre UK ISP Logo
100Mbps
Gift: None
toob UK ISP Logo
toob £19.50
150Mbps
Gift: None
Vodafone UK ISP Logo
Vodafone £22.00
150Mbps
Gift: None
Beebu UK ISP Logo
Beebu £23.00
100 - 160Mbps
Gift: None
Large Availability | View All
Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact