Netgear router vulnerabilities could let attackers 'roam untethered through an entire organization'
Vulnerabilities in Netgear routers opened the gates for attackers, according to Microsoft.
What you need to know
- Microsoft discovered three vulnerabilities in Netgear routers that could lead to identity theft and full system compromise.
- Netgear has already fixed the critical security issues.
- The issues affect Netgear DGN-2200v1 routers.
Microsoft disclosed several vulnerabilities to Netgear routers that could allow attackers to "roam untethered through an entire organization," according to the Microsoft 365 Defender Research Team. A post from that team breaks down the vulnerabilities. The vulnerabilities were patched before they were disclosed publicly.
There are three bugs that affect Netgear DGN-2200v1 series routers that are running firmware lower than v1.0.0.60. Microsoft's staff noticed the bugs due to an "odd behavior:"
Microsoft explains that the first issue allows for a "complete and fully reliable authentication bypass." This is due to the issue allowing an attacker to access any page on the vulnerable device.
The second issue allows for a side-channel attack that can be used to get authentication credentials.
The final issue allows attackers to gain access to secrets stored in the device. "After some preparatory steps, the contents are DES-encrypted with a constant key "NtgrBak," explains Microsoft. "This allows an attacker to get the plaintext password (which is stored in the encrypted NVRAM) remotely. The user name, which can very well be variations of 'admin', can be retrieved the same way."
The critical issues have been fixed by Netgear already. The company outlines the fixes in more detail in a recent post.
Get the Windows Central Newsletter
All the latest news, reviews, and guides for Windows and Xbox diehards.
Sean Endicott is a tech journalist at Windows Central, specializing in Windows, Microsoft software, AI, and PCs. He's covered major launches, from Windows 10 and 11 to the rise of AI tools like ChatGPT. Sean's journey began with the Lumia 740, leading to strong ties with app developers. Outside writing, he coaches American football, utilizing Microsoft services to manage his team. He studied broadcast journalism at Nottingham Trent University and is active on X @SeanEndicott_ and Threads @sean_endicott_.