BSI warns of security hole in 60 Netgear models
Summary
In January 2017 the BSI warned of a hole in around 60 Netgear router models through which attackers could read out the password of the web interface. It could be exploited if password recovery was disabled and the attacker was on the same network or remote management was active. The BSI rated the risk at level 5 without clearly explaining what that means.
Ideas
- Of all things, a disabled security function opened the hole.
- Remote management makes local holes reachable from the internet.
- Cable, VDSL and pure routers were affected alike.
Insights
- Remote management disabled by default is effective protection against mass attacks.
- Risk scales only help if their levels are explained understandably.
Facts
- Around 60 Netgear models were affected.
- Remote monitoring was disabled by default.
References
Critique
- The report only names the models without an update, not a complete list of affected devices.
Recommendations
- Leave routers’ remote management disabled and use a VPN if needed.
- After BSI warnings, check the manufacturer’s advice for your specific model.
- On devices without an update, enable password recovery, as Netgear advises as a workaround.
Links to the original source and the Web Archive open in a new tab.