Details of the vulnerability in NETGEAR Nighthawk WiFi6 Router (RAX30 AX2400)

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,600
Netgear has released a last-minute patch to close a vulnerability in the firmware of the Nighthawk WiFi6 router (RAX30 AX2400) on December 1, 2022. A misconfiguration allowed attackers in router firmware prior to version V1.0.9.90 to communicate with these devices from the Internet as if they were on the consumer's local network. In addition, the firmware's auto-update function seems to be broken. Security provider Tenable has now published details about this.

Tenable intended to use a vulnerability in Netgear routers on the Pwn2Own competition (December 6-8, 2022 in Toronto). But there was a last-minute patch from Netgear to close a vulnerability in the firmware of the Nighthawk WiFi6 router (RAX30 AX2400) on December 1, 2022. According to the manufacturer, the hotfix in the form of Netgear's RAX30 Firmware Version 1.0.9.90 addresses an unspecified vulnerability.

Tenable wrote that they actually wanted to exploit the vulnerability in a demo at the Pwn2Own contest. The fix released by Netgear effectively one day before the Pwn2Own registration deadline rendered their exploit ineffective. The security researchers have now published the details of the vulnerability, especially since the firmware's auto-update feature seems to be broken, as Tenable writes.
 

enaph

Level 28
Verified
Honorary Member
Top Poster
Well-known
Jun 14, 2011
1,790

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top