Netgear is advising customers to upgrade their firmware after it patched two critical vulnerabilities affecting multiple routers. The networking biz didn't reveal too much in the way of details for either vulnerability, including whether they had been exploited or not, but warned that if customers didn't follow the recommended steps their products would remain vulnerable. Netgear didn't release CVE identifiers for the vulnerabilities, opting instead for its own product security vulnerability (PSV) IDs: 2024-0117 and 2023-0039. The authentication bypass bug (2024-0117) scored 9.6 using the CVSSv3 framework while the unauthenticated remote code execution (RCE) flaw scored 9.8. The at-risk wireless AP models include two that have reached end of life (EOL): WAX206 and WAX220, as well as the WAX214v2 which is still supported with updates. We wouldn't want to speculate on what circumstances customers could find themselves in if either vulnerability were exploited without Netgear's input, but the severity of the flaws and the fact updates are being released even for EOL products are telling. All of the routers vulnerable to RCE are part of Netgear's Nighthawk gaming range and are still supported by product updates: XR100, XR1000v2, and XR500. Netgear's advisories were published over the weekend, but this week a whole host of national security and cybersecurity agencies in the US, UK, Canada, Australia, Czechia, Japan, and more, issued or co-signed guidance on securing edge devices. ...
Netgear critical vulns come amid global netsec concern
The Register
·Connor Jones
·Published Feb 5, 2025
·Updated
Affected Software
9 affected components
Netgear WAX206
Netgear WAX220
Netgear WAX214v2
Netgear XR100
Netgear XR1000v2
Netgear XR500
Netgear WAX206
Netgear WAX220
Netgear WAX214v2
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses critical vulnerabilities found in Netgear routers and the importance of firmware updates.
2
What security implications are discussed?
The vulnerabilities pose significant security risks that could potentially allow unauthorized access to devices.
3
What products or software are affected?
The affected products include the Netgear WAX206, WAX220, WAX214v2, XR100, XR1000v2, and XR500 routers.
4
What action does Netgear advise its customers to take?
Netgear advises customers to upgrade their firmware to address the identified vulnerabilities.
5
Are details provided about the vulnerabilities?
The article mentions that Netgear did not provide extensive details about the vulnerabilities.