TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Some Netgear Routers Need to Be Patched Immediately

31 点作者 j56no超过 3 年前

4 条评论

jeroenhd超过 3 年前
This may be a full RCE vulnerability but from what I can tell the exploit requires intercepting or redirecting HTTP traffic from the router to the update server.<p>Thats definitely a massive problem because anyone with access to DNS records (ISPs, governments, educational facilities, and so on) can remotely hack all of these devices, but on the other hand this poses no direct threat. The &quot;immediately&quot; part of the title seems overstated.<p>This just seems like a random, run-of-the-mill crappy router vulnerability to me. I&#x27;d be surprised if there was a consumer router that wasn&#x27;t vulnerable to this somehow. Good thing Netgear provides a patch, though.
评论 #28616952 未加载
ragesh超过 3 年前
I&#x27;m so glad I&#x27;ve been playing around with OpenWRT lately. I bought a second router a while back just to experiment with it and now I have automatic fail-over between two ISPs (with mwan3) and WPA2 Enterprise (with FreeRadius).<p>Needless to say, my Netgear R7000P will soon be decommissioned. I wish it were officially supported on OpenWRT because it&#x27;s got a good amount of RAM and flash that could have been put to better use.
评论 #28616689 未加载
评论 #28616680 未加载
评论 #28617731 未加载
szszrk超过 3 年前
<a href="https:&#x2F;&#x2F;kb.netgear.com&#x2F;000064039&#x2F;Security-Advisory-for-Remote-Code-Execution-on-Some-Routers-PSV-2021-0204" rel="nofollow">https:&#x2F;&#x2F;kb.netgear.com&#x2F;000064039&#x2F;Security-Advisory-for-Remot...</a><p>This link covers more the actual article.<p>TLDR: RCE on R6400v2 R6700 R6700v3 R6900 R6900P R7000 R7000P R7850 R7900 R8000 RS400
AdmiralAsshat超过 3 年前
Why the hell do I have to manually download the new firmware and deploy it to fix this? My Netgear router has usually been able to update itself in the past just by logging into the admin console and checking for new firmware updates.
评论 #28617700 未加载