Gandalf_The_Grey
Level 83
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
- Apr 24, 2016
- 7,256
Netgear has released a last-minute patch to close a vulnerability in the firmware of the Nighthawk WiFi6 router (RAX30 AX2400) on December 1, 2022. A misconfiguration allowed attackers in router firmware prior to version V1.0.9.90 to communicate with these devices from the Internet as if they were on the consumer's local network. In addition, the firmware's auto-update function seems to be broken. Security provider Tenable has now published details about this.
Tenable intended to use a vulnerability in Netgear routers on the Pwn2Own competition (December 6-8, 2022 in Toronto). But there was a last-minute patch from Netgear to close a vulnerability in the firmware of the Nighthawk WiFi6 router (RAX30 AX2400) on December 1, 2022. According to the manufacturer, the hotfix in the form of Netgear's RAX30 Firmware Version 1.0.9.90 addresses an unspecified vulnerability.
Tenable wrote that they actually wanted to exploit the vulnerability in a demo at the Pwn2Own contest. The fix released by Netgear effectively one day before the Pwn2Own registration deadline rendered their exploit ineffective. The security researchers have now published the details of the vulnerability, especially since the firmware's auto-update feature seems to be broken, as Tenable writes.
Details of the vulnerability in NETGEAR Nighthawk WiFi6 Router (RAX30 AX2400)
[German]Netgear has released a last-minute patch to close a vulnerability in the firmware of the Nighthawk WiFi6 router (RAX30 AX2400) on December 1, 2022. A misconfiguration allowed attackers in router firmware prior to version V1.0.9.90 to communicate with these devices from the Internet as if the
borncity.com