Yet Another Security Flaw Found In Netgear Routers

Seriously, what is up with Netgear these days?

After having some serious security flaws pop up last year, comes this latest one found by researcher Simon Kenin of Trustwave. According to this post, he found that by triggering an error message, the router can be tricked into handing over a numerical code that can then be used with the password recovery tool to retrieve the router’s administrator credentials. But what is worse is that Kenin also discovered that in many cases, the numerical code is not even necessary, and that random strings sent directly to the password recovery script would still cause the login information to be displayed. From there, it’s a trivial task to pwn the router. There are 31 different Netgear router models that are affected by this flaw and Netgear advises that you update your firmware right now.


You really have to wonder if Netgear takes the security of its products seriously. I get that any vendor can have security issues with their products. But the scale that Netgear seems to have these sorts of issues seems really high to me.


