advertisement
Forums

The Forum is sponsored by 
 

AAPL stock: Click Here

You are currently viewing the Tips and Deals forum
‘ If your Netgear Orbi router isn’t patched, you’ll want to change that pronto ‘
Posted by: btfc
Date: March 23, 2023 12:49PM
‘ Last year, researchers on Cisco’s Talos security team discovered four vulnerabilities and privately reported them to Netgear. The most severe of the vulnerabilities, tracked as CVE-2022-37337, resides in the access control functionality of the RBR750. Hackers can exploit it to remotely execute commands by sending specially crafted HTTP requests to the device. The hacker must first connect to the device, either by knowing the SSID password or by accessing an unprotected SSID. The severity of the flaw is rated 9.1 out of a possible 10.

In January, Netgear released firmware updates that patched the vulnerability. Now, Talos published a proof-of-concept exploit code along with technical details.

“The access control functionality of the Orbi RBR750 allows a user to explicitly add devices (specified by MAC address and a hostname) to allow or block the specified device when attempting to access the network,” Talos researchers wrote. “However, the dev_name parameter is vulnerable to command injection.” ‘


[arstechnica.com]
Options:  Reply • Quote
Re: ‘ If your Netgear Orbi router isn’t patched, you’ll want to change that pronto ‘
Posted by: Tiangou
Date: March 23, 2023 01:30PM
WiFi routers -- and Netgear's stuff in particular -- should be set to auto-update firmware wherever possible.



Options:  Reply • Quote
Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 157
Record Number of Users: 186 on February 20, 2020
Record Number of Guests: 5122 on October 03, 2020