Netgear Router Passwords Vulnerable to Hack, Firmware Fix Issued for Most Affected Models

Advertisement
By Shekhar Thakran | Updated: 1 February 2017 16:04 IST
Highlights
  • Netgear has issued a fix for 18 out of 31 vulnerable routers
  • The flaw was exposed by cyber-security firm Trustwave
  • Devices with remote management enabled vulnerable to hack

Netgear has issued firmware updates for several of its router models in response to a vulnerability, which was exposed by a cyber-security firm, on its devices that could reportedly be used by hackers to get full access to the device by recovering the admin password. Netgear has acknowledged that the vulnerability occurs when an attacker can access the internal network or when remote management is enabled on the router. The firmware updates follow a warning by US-CERT in December that along with Netgear identified three vulnerable routers made by the company.

Trustwave, the firm which disclosed the flaw, has claimed that the vulnerability is present on more than 10,000 devices that are remotely accessible. "The real number of affected devices is probably in the hundreds of thousands, if not over a million," Trustwave researcher Simon Kenin said in his blog post. In total, 31 models have been listed as vulnerable to the disclosed flaw and Netgear has issued a patch for 18. Two of the models that were previously listed as vulnerable are listed as non-vulnerable now, Kenin points out. The flaw allows attackers to access Web GUI login passwords while password recovery is disabled.

Advertisement

Lazy Encryption Practices Endanger Millions of Internet-Enabled Devices: Report

Even though the remote management feature is turned off by default on devices, it can be turned on through advanced settings by users, Netgear said in its post. The firmware fix has been made available by the company for the following models:

Advertisement
  • R8500
  • R8300
  • R7000
  • R6400
  • R7300DST
  • R7100LG
  • R6300v2
  • WNDR3400v3
  • WNR3500Lv2
  • R6250
  • R6700
  • R6900
  • R8000
  • R7900
  • WNDR4500v2
  • R6200v2
  • WNDR3400v2
  • D6220
  • D6400

Netgear has also released firmware fix for the Web password recovery vulnerability for model V6510. The company has also issued a workaround measure for those devices that are vulnerable but have not received the firmware fix as of now. The gist of the workaround is to manually enable password recovery feature and ensure that remote management is disabled.

Readers who are currently using Netgear branded devices are strongly advised to update their model by going to the dedicated page from company's official post in order to avoid being exposed to a hack.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Oppo K15 Pro Series With Active Cooling Fan Launched: See Price
  2. iQOO 15 Apex Edition Arrives in India as a Special Variant of iQOO 15
  3. Redmi Note 15 SE 5G to Launch With a Larger Battery Than Note 15 5G
  4. Oracle Begins Layoffs Affecting Thousands: Report
  5. Google Pixel 11 Pro Leaked Renders Hint at These Design Updates
  6. iQOO 15 Apex Colour Option Revealed, Will Launch in India on April 1
  7. OnePlus Nord 6 Camera Configuration Revealed as India Launch Draws Near
  8. Vivo V70 FE Roundup: Launch Date, Expected Price in India, Specifications
  9. Google Finally Lets Users Change Their Gmail Address
  10. Instagram Might Be Testing a 'Plus' Subscription With These Features
  1. OpenAI Raises $122 Billion in Latest Funding Round, Says Building Unified AI Superapp
  2. Bitcoin Price Rises to $69,000 as Ethereum Trades Near $2,100 Mark
  3. Nothing Reportedly Developing AI-Powered Smart Glasses, Earbuds as Part of Multi-Device Push
  4. Samsung Enables Blood Pressure Monitoring on Some Galaxy Watch Models in the US; Watch 9 Development Tipped
  5. Oppo K15 Pro+ and Oppo K15 Pro Launched With Active Cooling Fan, Up to 8,000mAh Battery: Price, Features
  6. Oracle to Reportedly Lay Off Thousands of Employees
  7. iQOO 15 Apex Edition Launched in India With 144Hz Refresh Rate, Snapdragon 8 Elite Gen 5 Chip: Price, Specifications
  8. Disney Reportedly Keen on Acquiring Fortnite Maker Epic Games at Some Point
  9. Lava Bold N2 Lite Launched in India With 5,000mAh Battery, 6.75-Inch Display: Price, Specifications
  10. Oppo K15 Pro Key Specifications Revealed Ahead of China Launch; Dimensity 8500 Super SoC Confirmed
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.