Netgear addressed a high-severity bug affecting multiple WiFi router models, including Wireless AC Nighthawk,Ā Wireless AX Nighthawk (WiFi 6), andĀ Wireless AC.
Netgear fixed a bug affecting multiple WiFi router models, including Wireless AC Nighthawk,Ā Wireless AX Nighthawk (WiFi 6), andĀ Wireless ACĀ router models.
The vendor only said that the flaw is a pre-authentication buffer overflow vulnerability and urged customers to address the firmware of their devices as soon as possible. An attacker can exploit this vulnerability without requiring permissions or user interaction.
Threat actors often exploit this kind of issue to trigger a DoS condition or to execute arbitrary code on vulnerable devices.
āNETGEAR has released fixes for a pre-authentication buffer overflowĀ security vulnerabilityā reads the advisory published by the company. āNETGEAR strongly recommends that you download the latest firmware as soon as possible.ā
Below is the list of fixes released by the company for the specific product models:
- RAX40Ā fixed in firmware versionĀ 1.0.2.60
- RAX35Ā fixed in firmware versionĀ 1.0.2.60
- R6400v2Ā fixed in firmware versionĀ 1.0.4.122
- R6700v3Ā fixed in firmware versionĀ 1.0.4.122
- R6900PĀ fixed in firmware versionĀ 1.3.3.152
- R7000PĀ fixed in firmware versionĀ 1.3.3.152
- R7000Ā fixed in firmware versionĀ 1.0.11.136
- R7960PĀ fixed in firmware versionĀ 1.4.4.94
- R8000PĀ fixed in firmware versionĀ 1.4.4.94
Below are step-by-step instructions to download the latest firmware for impacted router models:
- VisitĀ NETGEAR Support.
- Start typing your model number in the search box, then select your model from the drop-down menu as soon as it appears.
If you do not see a drop-down menu, make sure that you entered your model number correctly, or select a product category to browse for your product model. - ClickĀ Downloads.
- UnderĀ Current Versions, select the download whose title begins withĀ Firmware Version.
- ClickĀ Download.
- Follow the instructions in your productās user manual, firmware release notes, or product support page to install the new firmware.
āThe pre-authentication buffer overflowĀ vulnerability remains if you do not complete all recommended steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.ā concludes the advisory.
The vendor did don reveal if the flaw has been actively exploited in attacks in the wild.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
|
|
(SecurityAffairsĀ ā hacking, Netgear)
The post NETGEAR fixes a severe bug in its routers. Patch it asap! appeared first on Security Affairs.

