• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

HUGE exploit in Netgear Nighthawk and other routers, accessed by browsing the web

Status
Not open for further replies.

shanafan

Member
Stop buying crap consumer routers and get something like a ER Lite at the minimum for only $100

https://www.amazon.com/dp/B00CPRVF5K/?tag=neogaf0e-20

Pretty happy with my Nighthawk. Wireless works amazing in my 2 story, 2400 sq ft house with a basement. I'm upstairs, and my download was just 180 mbps at 27 ping. I really can not complain.

And newly patched as well of course, lmao.

what's a safe place to get dd-wrt r7000?
i don't see it on their official site at all?

Check my post on the last page at the bottom. I found it on Google, but their writeup on functionality didn't really tell me it was necessary to use their firmware over official firmware.
 

Primus

Member
what's a safe place to get dd-wrt r7000?
i don't see it on their official site at all?

Nighthawks should be using the Kong builds of DD-WRT, those are available at http://desipro.de/ddwrt/K3-AC-Arm/. Latest version is 30910M, dated 20161202.

Get the .chk version that corresponds to your particular router model (the 7000, in your case), and flash to that from the Netgear admin panel.

EDIT: Initial flash and reboot will take a few minutes, don't be alarmed. The main Kong thread, with all kinds of tips and guide and help, is here.
 

omgkitty

Member
As someone who only uses their router to connect to the internet in a basic capacity, what would be the reason to use a custom firmware, besides some security upgrades?
 

n0razi

Member
Pretty happy with my Nighthawk. Wireless works amazing in my 2 story, 2400 sq ft house with a basement. I'm upstairs, and my download was just 180 mbps at 27 ping. I really can not complain.

A Prosumer Ubiquiti router has almost no performance benefit (if any) over a consumer router... you are choosing rock solid reliability and secure software.
 
I have nothing but great things to say about my R7000 Nighthawk.

I bought my parents an Asus AC-68U and while the router configuration tool has a snazzy interface compared to the Netgear, it has clearly inferior range to the R7000.

People who act like this is the first time a router has ever had a vulnerability have literally no clue. Netgear ignoring it for 3 months is seriously bad though, maybe this will light a fire under their asses to investigate and fix reported vulnerabilities before people go public with them.
 

jiggle

Member
Nighthawks should be using the Kong builds of DD-WRT, those are available at http://desipro.de/ddwrt/K3-AC-Arm/. Latest version is 30910M, dated 20161202.

Get the .chk version that corresponds to your particular router model (the 7000, in your case), and flash to that from the Netgear admin panel.

EDIT: Initial flash and reboot will take a few minutes, don't be alarmed. The main Kong thread, with all kinds of tips and guide and help, is here.

Thanks
Looks like the 2014 version is working on blocking this
So I don't need the get the newest one ya?
 

MuggerMD

Banned
Just read through the thread. I've got the R7000 and just updated to the Netgear beta patch.

I'm trying to figure out the benefit for the casual user to go to an aftermarket firmware?
 
Just ran the Netgear Genie to upgrade my R7800 to latest official firmware.

Bricked.

It's just a blinking white power light, which means corrupted firmware in the manual.

Just fucking wonderful.

Now I'm screwed out of internet. Why does this shit happen to me?

Spent 2 hours trying to TFTP flash it manually too - still just a white blinking power light.

So, any recommendations for a better router, comparable to the Nighthawk's abilities and range? But WAY MORE RELIABLE? Thanks
 

Primus

Member
Thanks
Looks like the 2014 version is working on blocking this
So I don't need the get the newest one ya?

Absolutely get the newest version. It's pretty stable from forum posts, and has tons of bugfixes and a much newer Linux kernel than the 2014 version.
 

BobLoblaw

Banned
When I first saw this thread I was like "Fuck this shit!" I just bought a Netgear Nighthawk...C7000.

Tiger-Woods-fistpump-slow-motion.gif
 

marc^o^

Nintendo's Pro Bono PR Firm
For whatdver reasin I can't access routerlogin.net from my computer where I have the beta firmware. It says I should be connected inwigi (I'm on ethernet). I temived my RJ45 cable, this time I'm connected in wifi, but I still get the message. So I can't accesd my administration console :-/
 

saunderez

Member
For whatdver reasin I can't access routerlogin.net from my computer where I have the beta firmware. It says I should be connected inwigi (I'm on ethernet). I temived my RJ45 cable, this time I'm connected in wifi, but I still get the message. So I can't accesd my administration console :-/

Take a look at your IP settings (presumably you're using DHCP) see what IP your default gateway is and try using that instead of routerlogin.net.
 

Rymuth

Member
Well, don't I have an egg on my face...bought a Nighthawk last week (I hate it) and the punches keep on rolling...
 

IISANDERII

Member
Actually they did inform customers who registered their hardware online, I got the email about the time it was discovered along with a link to the fix.
This is the first time I've heard about a benefit to registering their product.

This is the first time I've heard somebody registering their product.
 
Nighthawks should be using the Kong builds of DD-WRT, those are available at http://desipro.de/ddwrt/K3-AC-Arm/. Latest version is 30910M, dated 20161202.

Get the .chk version that corresponds to your particular router model (the 7000, in your case), and flash to that from the Netgear admin panel.

EDIT: Initial flash and reboot will take a few minutes, don't be alarmed. The main Kong thread, with all kinds of tips and guide and help, is here.

Does it work fine with IPV6? I'm using Merlin right now. How does this version of DD-WRT compare?
 
I've been meaning to upgrade anyway, so with this news I've upgraded to an Asus RT-AC88U AC3100 router and an Asus PCE-AC88 AC3100 Wireless Adapter for my gaming PC.

Gigabit Wi-Fi here I come!!! Should help a ton with Steam In-Home Streaming and PS4 Pro Remote Play. I've got my PS4 Pro and my Steam Link on gigabit ethernet, but my PC was always the bottleneck in the past. Not anymore!
 

Jams775

Member
Had to go back to the beta firmware after trying the latest KONG build. It just wasn't stable and I was having trouble connecting devices. At least the Beta patch seems to fix the issue.
 

Afrikan

Member
Jesus..

First Yahoo and now maybe my NetGear router?

I'm fucked. Maybe I should start over...and start a new *online life*.
 
I had that router, and it gave me very fast but inconsistent signal, which kept dropping. Make sure to not use the USB 3.0 port.

What'd you replace it with? Honestly curious, because there's always time to cancel my order if there's a better router out there. This one was right at the top from the hour or two of research I did.

As for inconsistent signal, all the reviews I've read suggested it was stable as a rock in their stress tests, so I'm not sure why you were having issues.

I will not be using any type storage device on the router, so I'm not concerned with USB 3.0.
 
Downloaded the beta firmware for the R8000 and now my connection drops for 10 seconds or so seemingly every few minutes.
Great.
 

Afrikan

Member
just got home, and yup I have the R6250

so what do they want us to do? just chill?


Downloaded the beta firmware for the R8000 and now my connection drops for 10 seconds or so seemingly every few minutes.
Great.

and I don't want this to happen to me. I rarely have connection issues with my router. :/
 
What'd you replace it with? Honestly curious, because there's always time to cancel my order if there's a better router out there. This one was right at the top from the hour or two of research I did.

As for inconsistent signal, all the reviews I've read suggested it was stable as a rock in their stress tests, so I'm not sure why you were having issues.

I will not be using any type storage device on the router, so I'm not concerned with USB 3.0.
It's possible I just got a dud, but I ended up replacing with an AmpliFi HD mesh setup.
 

Anion

Member
Gosh I have been having issues with this router no matter how many times I restart or reset it. I'm done with netgear. I absolutely loved this router at first and now I guess it just has died on me slowly. I might try that other alternative dd-rt firmware before I chuck this out

What the latest best thing nowadays?
 

Raticus79

Seek victory, not fairness
Thanks for the heads up - had an R8000 here.

Wonder if someone could write a web page that abuses the vulnerability to install the updated firmware, heh
 

Ramma2

Member
Same for the R6400. Update details:

New firmware is found. Do you want to update the firmware?
Current GUI Language Version: 1.0.1.12_2.1.38.1
New GUI Language Version: 1.0.1.18_2.1.38.1
Current Firmware Version 1.0.1.12
New Firmware Version 1.0.1.18_1.0.15
Release Notes:
1. [Bug Fix] Fixed the security issue about Security Advisory VU 582384.
 

Bboy AJ

My dog was murdered by a 3.5mm audio port and I will not rest until the standard is dead
Got an email from Netgear.

NETGEAR constantly monitors for both known and unknown threats. Being pro-active rather than re-active to emerging security issues is fundamental for product support at NETGEAR.
Liars.
 
Just ran the Netgear Genie to upgrade my R7800 to latest official firmware.

Bricked.

It's just a blinking white power light, which means corrupted firmware in the manual.

Just fucking wonderful.

Now I'm screwed out of internet. Why does this shit happen to me?

Spent 2 hours trying to TFTP flash it manually too - still just a white blinking power light.

So, any recommendations for a better router, comparable to the Nighthawk's abilities and range? But WAY MORE RELIABLE? Thanks

the r7800 isn't one of the affected though, right?
 

jiggle

Member
It's not beta anymore right?

Guess I'll go back to official firmware
I'm getting more frequent dropped connection with ddwrt
 

Chanser

Member
Just ran the Netgear Genie to upgrade my R7800 to latest official firmware.

Bricked.

It's just a blinking white power light, which means corrupted firmware in the manual.

Just fucking wonderful.

Now I'm screwed out of internet. Why does this shit happen to me?

Spent 2 hours trying to TFTP flash it manually too - still just a white blinking power light.

So, any recommendations for a better router, comparable to the Nighthawk's abilities and range? But WAY MORE RELIABLE? Thanks

Why did you flash? It's not even on the list.
 

shockdude

Member
Probably the silliest thing about this exploit is that, if you've connected your router to an internet modem, then the modem firewall is most likely already doing its job of blocking the exploit in the first place. I just tried connecting to my IP with my phone and wasn't able to trigger the exploit, despite being able to trigger it on my local network with my laptop.

Good to see it properly fixed, though.

Edit: Just did the firmware update, nothing bad so far and the exploit seems fixed. Awesome.
 
Status
Not open for further replies.
Top Bottom