What Is the Latest Netgear Router Firmware

What Is the Latest Netgear Router Firmware

Millions of Netgear routers need security updates correct away — what yous demand to do

Netgear Nighthawk RAXE500 review



(Prototype credit: Netgear)

Got a Netgear router? I practise, and like yours, mine probably needs to exist patched right away.

That’due south considering the enterprising folks at D.C.-area security firm
Grimm
have found yet another very serious Netgear flaw, as detailed in a report Nov. 16. This comes (relatively) hot on the heels of the
previous agglomeration of Netgear security updates back in September
of this year.

This time around,
Netgear lists more than xl different models
(opens in new tab)


of routers, range extenders and a couple of other devices, from models nearly a decade old to brand-new models on our list of the
all-time Wi-Fi routers, that need to install firmware updates to protect themselves from total hacker takeover.

Unfortunately, nearly 40 other Netgear models may non become whatsoever updates, equally many of them are already too former to get any further support.

We’ve got a listing of all the affected models at the finish of this story. All together, nosotros’re looking at about 80 different models of Wi-Fi routers, Wi-Fi range extenders, DSL gateways and other devices. The number of affected individual units has to be at to the lowest degree several hundred thousand, and may be in the low millions.

How to update your Netgear router’s firmware

The newer your Netgear router is, the easier information technology is to update the firmware. Netgear’s
Orbi mesh routers
generally update themselves, and they likewise have a companion smartphone app that you lot can utilize to check for and to install updates.

Netgear’s
Nighthawk routers
also accept a companion app, although using it is optional for at least some models, as is the automated-update setting. With some Nighthawks, it’s generally all-time to become into the administrative interface (try “http://192.168.1.1/admin” or “routerlogin.net” while continued to your dwelling house network) and check the “Advanced” department for firmware updates. From there, you should be able to launch the update sequence.

If the above methods don’t piece of work with your Netgear router, and so y’all need to go to Netgear support at https://www.netgear.com/support/ and type in the model number of your router in the search filed at the top of the page. (We’ve got more than instructions here on
how to update your router’s firmware.)

Nevertheless, the model number may not be obvious. Some routers come up with their branding and specifications proudly listed on the box, such equally “Nighthawk AXE11000 Tri-Ring WiFi 6E.” But that’due south non the model name, which is really “RAXE500.” (That’s the router in the photo at the top of this story, and it does need to exist patched.)

Read:  Cara Mengetahui Password Wifi Printer Canon G3010

Look for a sticker on the router itself displaying the model number — it may exist on the side or on the bottom. To further complicate things, Netgear sometimes changes the inner circuits of a router while leaving the exterior the same during the production lifespan, so you may run across a “v2” or “v3” appended to the model number.

Once you have the model number, the search function on the Netgear back up site should take you lot to that model’s support folio. Ringlet downward the page to find “Firmware and Software Downloads” and click it.

You lot’ll and so see a push button that will permit you lot download the firmware update to your PC or Mac. Do that, but don’t forget to click the Release Notes link just below it, which in plough will atomic number 82 you to a link that leads to a downloadable version of your router’s user transmission, which will show y’all how to install the firmware update. The firmware update itself may come up with its own instructions.

And then what is this Netgear flaw that’s being fixed?

The fatal flaw in all of these models involves a stack-overflow vulnerability in the Universal Plug and Play component of the router firmware. The flaw is catalogued as CVE-2021-34991 and is listed every bit applying to only one specific router with a specific firmware version, which got an update on Sept. 16. But the trouble is much more widespread than that.

Universal Plug and Play,  or UPnP for short, is a protocol that lets new devices, such as gaming consoles or printers, connect to routers without a lot of fuss. It turns out that a character limit in one function of the UPnP protocol on these Netgear routers permits an attacker on the local network — i.e., already linked to your router as a regular user — to send a malicious command to the router that overrides the routers internal safeguards and gives the router total control without whatsoever kind of authorization.

In one case that’southward done, the attacker can pretty much encounter anything you exercise online, and tin can also ship you lot to malicious websites or pause into more devices on your network.

Yous may think that it’s enough to just go on intruders out of your network to prevent such an assault, only it’due south not that difficult to
crevice a Wi-Fi network access password
or to sneak malicious software onto a poorly secured device, such as an out-of-appointment computer or a smart-home device.

Read:  Zhiyun-tech Remote Control for Crane 2 Firmware Update

Suffice it to say that you want to install the Netgear firmware update on your router tout suite — if you tin.

Netgear routers with firmware patches available

Hither’s a list, copied from the Netgear website, of the models that take firmware updates or “hot fixes” available to ready this flaw, forth with the about recent firmware version that they should be updated to.

Routers:

  •     R6400 stock-still in firmware version i.0.1.76
  •     R6400v2 fixed in firmware version one.0.4.120
  •     R6700v3 stock-still in firmware version 1.0.4.120
  •     R6900P stock-still in firmware version i.3.three.142_HOTFIX
  •     R7000 fixed in firmware version i.0.11.128
  •     R7000P fixed in firmware version 1.3.3.142_HOTFIX
  •     R7100LG fixed in firmware version i.0.0.72
  •     R7850 stock-still in firmware version i.0.5.76
  •     R7900P fixed in firmware version 1.4.2.84
  •     R7960P fixed in firmware version 1.four.2.84
  •     R8000 fixed in firmware version 1.0.4.76
  •     R8000P fixed in firmware version 1.4.2.84
  •     R8300 fixed in firmware version one.0.2.156
  •     R8500 fixed in firmware version one.0.2.156
  •     RAX15 stock-still in firmware version one.0.4.100
  •     RAX20 stock-still in firmware version one.0.4.100
  •     RAX200 fixed in firmware version 1.0.5.132
  •     RAX35v2 fixed in firmware version one.0.iv.100
  •     RAX38v2 stock-still in firmware version 1.0.4.100
  •     RAX40v2 fixed in firmware version 1.0.4.100
  •     RAX42 fixed in firmware version i.0.4.100
  •     RAX43 fixed in firmware version 1.0.4.100
  •     RAX45 stock-still in firmware version one.0.4.100
  •     RAX48 fixed in firmware version 1.0.4.100
  •     RAX50 fixed in firmware version 1.0.4.100
  •     RAX50S fixed in firmware version i.0.4.100
  •     RAX75 fixed in firmware version one.0.5.132
  •     RAX80 fixed in firmware version ane.0.five.132
  •     RAXE450 fixed in firmware version 1.0.8.70
  •     RAXE500 stock-still in firmware version 1.0.8.70
  •     RS400 fixed in firmware version 1.5.1.80
  •     WNDR3400v3 fixed in firmware version i.0.1.42
  •     WNR3500Lv2 fixed in firmware version 1.ii.0.70
  •     XR300 fixed in firmware version i.0.iii.68

DSL Modem Routers:

  •     D6220 fixed in firmware version one.0.0.76
  •     D6400 stock-still in firmware version 1.0.0.108
  •     D7000v2 fixed in firmware version one.0.0.76
  •     DGN2200v4 fixed in firmware version 1.0.0.126

Wi-Fi extenders:

  •     EX3700 fixed in firmware version 1.0.0.94
  •     EX3800 stock-still in firmware version 1.0.0.94
  •     EX6120 fixed in firmware version i.0.0.66
  •     EX6130 fixed in firmware version 1.0.0.66

AirCards:

  •     DC112A fixed in firmware version 1.0.0.62

Cable Modems:

  •     CAX80 fixed in firmware version 2.1.3.5

Netgear models that may or may non get a firmware update

Here’s a list of Netgear models that the Grimm team determined were vulnerable to these attacks, but which Netgear hasn’t specifically listed as getting patches for this flaw. The firmware version numbers listed below ARE vulnerable, according to Grimm.

Unfortunately, there are models on Netgear’s list of patches that aren’t on Grimm’south list of vulnerable devices. And there are models on Grimm’s listing that aren’t on Netgear’s listing, nevertheless have received security patches in the terminal few months that pushed the firmware versions across the vulnerable ones listed beneath, so they may really take bachelor patches for this flaw.

Read:  Wer Nutzt Firmware 11.2.3 Auf Meinem Tolino Vision 3 Hd Mit Anderen Leseapps

To complicate things further, at that place are six models that Grimm says are not vulnerable because past firmware updates “broke” UPnP for them. 4 of those — D6220, D6400, R6400 and R7000 — are on Netgear’s list of patched models. Two others, D8500 and R6300v2, are non, and the only available firmware updates for them are the vulnerable ones listed below.

The best matter to do, if you have one of the models listed below, is to follow the procedures in a higher place about checking to see if a firmware update is bachelor for your model on the Netgear support site.

If the bachelor firmware update has a version number afterwards than what’southward beneath, then y’all may be getting a patch for the to a higher place flaw, especially if the release note for the flaw has a date in the by few months. Go alee and install the update.

But if the version number of the available firmware update matches the firmware number below, and the release-note date is more than than a few months old, then information technology might exist time to get a new router.

  • AC1450 – ane.0.0.36
  • D6300 – one.0.0.102
  • D8500 – 1.0.3.60
  • DGN2200M – 1.0.0.35
  • DGND3700v1 – 1.0.0.17
  • EX3920 – 1.0.0.88
  • EX6000 – 1.0.0.44
  • EX6100 – 1.0.two.28
  • EX6150 – ane.0.0.46
  • EX6920 – 1.0.0.54
  • EX7000 – 1.0.one.94
  • MVBR1210C – one.2.0.35BM
  • R4500 – 1.0.0.4
  • R6200 – 1.0.ane.58
  • R6200v2 – 1.0.3.12
  • R6250 – 1.0.4.48
  • R6300 – 1.0.ii.80
  • R6300v2 – 1.0.4.52
  • R6700 – 1.0.ii.16
  • R6900 – one.0.two.sixteen
  • R7300DST – 1.0.0.74
  • R7900 – 1.0.4.38
  • WGR614v9 – 1.two.32
  • WGT624v4 – 2.0.13
  • WNDR3300v1 – 1.0.45
  • WNDR3300v2 – 1.0.0.26
  • WNDR3400v1 – ane.0.0.52
  • WNDR3400v2 – 1.0.0.54
  • WNDR3700v3 – ane.0.0.42
  • WNDR4000 – 1.0.two.10
  • WNDR4500 – 1.0.1.46
  • WNDR4500v2 – ane.0.0.72
  • WNR834Bv2 – ii.1.13
  • WNR1000v3 – one.0.ii.78
  • WNR2000v2 – 1.ii.0.12
  • WNR3500 – 1.0.36NA
  • WNR3500v2 – i.ii.2.28NA
  • WNR3500L – 1.2.2.48NA

Paul Wagenseil is a senior editor at Tom’s Guide focused on security and privacy. He has likewise been a dishwasher, fry cook, long-booty driver, code monkey and video editor. He’s been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom’s Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random Boob tube news spots and even moderated a panel discussion at the CEDIA home-engineering briefing. Y’all tin follow his rants on Twitter at
@snd_wagenseil.


What Is the Latest Netgear Router Firmware

You May Also Like