Security

Netgear addresses severe security flaws in 20 of its products

Netgear has released security updates to address high-severity vulnerabilities affecting several of its smart switches used by businesses.

Netgear has released firmware updates to address high-severity vulnerabilities in more than a dozen of its smart switches used on businesses.

The company fixed three security flaws that affect 20 Netgear products, mostly smart switches. Technical details and proof-of-concept (PoC) exploit code for two of the bugs are publicly available.

Netgear has addressed three vulnerabilities tracked by the vendor as PSV-2021-0140, PSV-2021-0144, PSV-2021-0145 that received a CVSS score between 7.4 and 8.8.

The flaws affected multiple products including the following smart switches, below is the list of the impacted devices and related firmware fixes:

  • GC108P fixed in firmware version 1.0.8.2
  • GC108PP fixed in firmware version 1.0.8.2
  • GS108Tv3 fixed in firmware version 7.0.7.2
  • GS110TPP fixed in firmware version 7.0.7.2
  • GS110TPv3 fixed in firmware version 7.0.7.2
  • GS110TUP fixed in firmware version 1.0.5.3
  • GS308T fixed in firmware version 1.0.3.2
  • GS310TP fixed in firmware version 1.0.3.2
  • GS710TUP fixed in firmware version 1.0.5.3
  • GS716TP fixed in firmware version 1.0.4.2
  • GS716TPP fixed in firmware version 1.0.4.2
  • GS724TPP fixed in firmware version 2.0.6.3
  • GS724TPv2 fixed in firmware version 2.0.6.3
  • GS728TPPv2 fixed in firmware version 6.0.8.2
  • GS728TPv2 fixed in firmware version 6.0.8.2
  • GS750E fixed in firmware version 1.0.1.10
  • GS752TPP fixed in firmware version 6.0.8.2
  • GS752TPv2 fixed in firmware version 6.0.8.2
  • MS510TXM fixed in firmware version 1.0.4.2
  • MS510TXUP fixed in firmware version 1.0.4.2

Two of the vulnerabilities were reported by security researcher Gynvael Coldwind who also released a PoC exploit code for both issues.

“NETGEAR GS110TPV3 Smart Managed Pro Switch with SCC Control enabled* is vulnerable to an authentication bypass resulting in the attacker being able to change admin’s password (among other things), resulting in a full compromise of the device.” explained Coldwind.

The experts pointed out that SCC Control (NETGEAR Smart Control Center) is disabled by default, and must be manually enabled in the web UI (Security > Management Security > SCC Control). The researcher also published a PoC code that changes the password to “AlaMaKota1234.”

NETGEAR on the advisory page rated the issue with a CVSS score of 8.8 (High), while Coldwind assigned it a score of 9.8 because “network should be used even if the attacker is required to be on the same intranet to exploit the vulnerable system (e.g., the attacker can only exploit the vulnerability from inside a corporate network).”

The second vulnerability reported by the expert is an authentication hijacking issue.

“NETGEAR GS110TPV3 Smart Managed Pro Switch is vulnerable to authentication hijacking (for lack of a better term) that allows an attacker with the same IP as a logging in admin to hijack the session bootstrapping information, giving the attacker full admin access to the device web UI and resulting in a full compromise of the device.” reads the advisory published by the researcher.”The obvious limiting factor here is the requirement for the attacker to either have the same IP as the admin (foothold on the same machine with limited privileges, same source NAT IP, etc) or being able to spoof the IP with various low-level network shenanigans, as well winning a race condition with a 1-second window (pretty easy actually).”

The researcher also released a PoC exploit that will attempt to win the race and hijack session bootstrap information.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Netgear)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

MITRE revealed that nation-state actors breached its systems via Ivanti zero-days

The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by…

18 hours ago

FBI chief says China is preparing to attack US critical infrastructure

China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher…

1 day ago

United Nations Development Programme (UNDP) investigates data breach

The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack…

1 day ago

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

2 days ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

2 days ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

2 days ago

This website uses cookies.