Categories: Network Security

Unpatched zero-day Flaw in 79 Netgear Routers Allows Hacker to take Full Control of the Device

Researchers discovered unpatched zero-day vulnerability with 79 Netgear routers that allow attackers to take control over the device remotely.

The flaw allows attackers to run arbitrary code as “root” user and to take full control over the device remotely.

79 Netgear Routers Models Vulnerable

The vulnerabilities were discovered by two security researchers Adam Nichols from GRIMM and d4rkn3ss from Internet service provide VNPT.

Nicholas discovered that vulnerability could affect 758 different firmware versions that run on 79 Netgear routers. The firmware is released back in 2007.

According to the reports, the vulnerability resides HTTPD service that listens on TCP port 80 by default. The issue is due to improper validation of “user-supplied data before copying it to a fixed-length, stack-based buffer.”

The vulnerability allows hackers to execute arbitrary code on vulnerable devices as a root user. Authentication is not required to exploit this vulnerability.

Adam Nichols analyzed the vulnerability Netgear R7000 version 1.0.9.88 firmware and used the binwalk to extract the root filesystem from the firmware image.

The vulnerability can be exploitable only with the older versions, in modern software this vulnerability would be unexploitable as the modern software typically contains stack cookies.

Researchers also developed an exploit that served as a CSRF attack, “If a user with a vulnerable router browses to a malicious website, that website could exploit the user’s router.”

Routers and modems are the important security borders that prevent attacks from directly exploiting the computers in a network.

Affected router models;

AC1450MBR1516WGR614v9
D6220MBRN3000WGR614v10
D6300MVBR1210CWGT624v4
D6400R4500WN2500RP
D7000v2R6200WN2500RPv2
D8500R6200v2WN3000RP
DC112AR6250WN3100RP
DGN2200R6300WN3500RP
DGN2200v4R6300v2WNCE3001
DGN2200MR6400WNDR3300
DGND3700R6400v2WNDR3300v2
EX3700R6700WNDR3400
EX3800R6700v3WNDR3400v2
EX3920R6900WNDR3400v3
EX6000R6900PWNDR3700v3
EX6100R7000WNDR4000
EX6120R7000PWNDR4500
EX6130R7100LGWNDR4500v2
EX6150R7300WNR834Bv2
EX6200R7850WNR1000v3
EX6920R7900WNR2000v2
EX7000R8000WNR3500
LG2200DR8300WNR3500v2
MBM621R8500WNR3500L
MBR624GURS400WNR3500Lv2
MBR1200WGR614v8XR300
MBR1515

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

New Mozi P2P Botnet Attacks Netgear, GPON, D-Link and Huawei Routers Using Weak Passwords and Some Known Exploits

Multiple Vulnerabilities with NETGEAR Wireless Routers Allows Attackers to Access Sensitive Information

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Threat Actors Leverage Email Bombing to Evade Security Tools and Conceal Malicious Activity

Threat actors are increasingly using email bombing to bypass security protocols and facilitate further malicious…

7 hours ago

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral to…

7 hours ago

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers, following…

7 hours ago

Threat Actors Exploit Legitimate Crypto Packages to Deliver Malicious Code

Threat actors are using open-source software (OSS) repositories to install malicious code into trusted applications,…

7 hours ago

Tycoon 2FA Phishing Kit Uses Advanced Evasion Techniques to Bypass Endpoint Detection Systems

The notorious Tycoon 2FA phishing kit continues its evolution with new strategies designed to slip…

7 hours ago

Hands-On Labs: The Key to Accelerating CMMC 2.0 Compliance

INE Security Highlights How Practical, immersive training environments help defense contractors meet DoD cybersecurity requirements…

11 hours ago