Security holes patched 11 vulnerable Netgear routers with final updates

Spread the love

Vulnerabilities in 11 Netgear routers that could allow a remote attacker to run arbitrary code as root have been patched with final updates. These patches can be downloaded and installed via the web interface of the routers.

The updates for the 11 models in the R6000, R7000, R8000 and D6000 series can be downloaded from the Netgear website. To date, only beta updates have been available for the majority of routers and final updates have been available for three models. The vulnerability was announced at the beginning of this month and the manufacturer has been working on a fix since then. Netgear recommends that users of the routers install the updates even if they have previously installed the beta firmware.

According to the American Cert of Carnegie Mellon University, exploits for the vulnerability in the routers are already available. These offer the possibility to perform command injection when the user of an affected router can, for example, be lured to a malicious website.

A beta firmware has also been released for the Netgear WNR2000 router, which was revealed to have another vulnerability last week. The hole is in the remote management feature. Users can also disable this feature to temporarily close the vulnerability.

You might also like
Exit mobile version