• News/
  • https://www.theregister.com/2025/02/05/netgear_fixes_critical_bugs_while/

Netgear critical vulns come amid global netsec concern

The Register
·
Connor Jones
·
Published Feb 5, 2025
·
Updated

Netgear is advising customers to upgrade their firmware after it patched two critical vulnerabilities affecting multiple routers. The networking biz didn't reveal too much in the way of details for either vulnerability, including whether they had been exploited or not, but warned that if customers didn't follow the recommended steps their products would remain vulnerable. Netgear didn't release CVE identifiers for the vulnerabilities, opting instead for its own product security vulnerability (PSV) IDs: 2024-0117 and 2023-0039. The authentication bypass bug (2024-0117) scored 9.6 using the CVSSv3 framework while the unauthenticated remote code execution (RCE) flaw scored 9.8. The at-risk wireless AP models include two that have reached end of life (EOL): WAX206 and WAX220, as well as the WAX214v2 which is still supported with updates. We wouldn't want to speculate on what circumstances customers could find themselves in if either vulnerability were exploited without Netgear's input, but the severity of the flaws and the fact updates are being released even for EOL products are telling. All of the routers vulnerable to RCE are part of Netgear's Nighthawk gaming range and are still supported by product updates: XR100, XR1000v2, and XR500. Netgear's advisories were published over the weekend, but this week a whole host of national security and cybersecurity agencies in the US, UK, Canada, Australia, Czechia, Japan, and more, issued or co-signed guidance on securing edge devices. ...

Read full article

Affected Software

9 affected components
Netgear WAX206
Netgear WAX220
Netgear WAX214v2
Netgear XR100
Netgear XR1000v2
Netgear XR500
Netgear WAX206
Netgear WAX220
Netgear WAX214v2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses critical vulnerabilities found in Netgear routers and the importance of firmware updates.

2

What security implications are discussed?

The vulnerabilities pose significant security risks that could potentially allow unauthorized access to devices.

3

What products or software are affected?

The affected products include the Netgear WAX206, WAX220, WAX214v2, XR100, XR1000v2, and XR500 routers.

4

What action does Netgear advise its customers to take?

Netgear advises customers to upgrade their firmware to address the identified vulnerabilities.

5

Are details provided about the vulnerabilities?

The article mentions that Netgear did not provide extensive details about the vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203