• News/
  • https://www.bleepingcomputer.com/news/security/netgear-warns-users-to-patch-critical-wifi-router-vulnerabilities/

Netgear warns users to patch critical WiFi router vulnerabilities

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 4, 2025
·
Updated

Netgear has fixed two critical vulnerabilities affecting multiple WiFi router models and urged customers to update their devices to the latest firmware as soon as possible. The security flaws impact multiple WiFi 6 access points (WAX206, WAX214v2, and WAX220) and Nighthawk Pro Gaming router models (XR1000, XR1000v2, XR500). Although the American computer networking company did not disclose more details about the two bugs, it did reveal that unauthenticated threat actors can exploit them for remote code execution (tracked internally as PSV-2023-0039) and authentication bypass (PSV-2021-0117) in low-complexity attacks that don't require user interaction. "NETGEAR strongly recommends that you download the latest firmware as soon as possible," the company said in security advisories published over the weekend. The table below lists all vulnerable router models and the firmware versions with security patches. To download and install the latest firmware for your Netgear router, you have to go through the following steps: "The unauthenticated RCE vulnerability remains if you do not complete all recommended steps," the company warned on Saturday. "NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification." A Netgear spokesperson was not available for comment when contacted by BleepingComputer for more information on the two security flaws. In July, Netgear also urged customers to update to the latest firmware i...

Read full article

Affected Software

12 affected components
Netgear WAX206
Netgear WAX214v2
Netgear WAX220
Netgear XR1000
Netgear XR1000v2
Netgear XR500
Netgear WiFi 6 access point=WAX206
Netgear WiFi 6 access point=WAX214v2
Netgear WiFi 6 access point=WAX220
Netgear Nighthawk Pro Gaming Router=XR1000
Netgear Nighthawk Pro Gaming Router=XR1000v2
Netgear Nighthawk Pro Gaming Router=XR500
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are Netgear users being warned about?

Netgear users are being warned about two critical vulnerabilities affecting multiple WiFi router models.

2

Which Netgear products are impacted by these vulnerabilities?

The affected products include the Netgear WAX206, WAX214v2, WAX220, XR1000, XR1000v2, and XR500 routers.

3

What should Netgear customers do to protect their devices?

Netgear customers are urged to update their devices to the latest firmware as soon as possible.

4

What potential risks do these vulnerabilities pose to users?

These vulnerabilities could potentially allow attackers to compromise the routers and gain unauthorized access to the network.

5

How can users verify if their Netgear router needs a firmware update?

Users can check the Netgear website or their router's settings interface for the latest firmware version available for their device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203