It's another reason once you bought a router to reflash it with alternative firmwares as OpenWRT or DD-WRT
The last time I looked into OpenWRT/DD-WRT (years ago), it seemed disadvantageous to switch to them because they would be slower than stock firmware due to missing some kind of hardware support. Is this still the case these days? EDIT: It sounds like the situation for my router (R7000) is quite the opposite now, apparently being almost twice as fast due to new hardware acceleration features.
Netgear 0-day vulnerability analysis and exploit
21–30 of 102 posts
Re: Netgear 0-day vulnerability analysis and exploit
#22The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…
Another brand i vouch for is AVM, their routers are all over Germany and they're reliable workhorses for years... Maybe, just maybe, someone should start a list with vendors that put out shitty software on their devices, never deliver firmware updates and have stupid exploits...
You might as well just list every vendor, the exceptions are rare and don't always last.
Re: Netgear 0-day vulnerability analysis and exploit
#23The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…
Re: Netgear 0-day vulnerability analysis and exploit
#24The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…
Re: Netgear 0-day vulnerability analysis and exploit
#25The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…
Re: Netgear 0-day vulnerability analysis and exploit
#26It's another reason once you bought a router to reflash it with alternative firmwares as OpenWRT or DD-WRT
Re: Netgear 0-day vulnerability analysis and exploit
#27 In SOHO devices like the R7000, the web server must parse user input
from the network and run complex CGI functions that use that input.
Furthermore, the web server is written in C and has had very little testing,
and thus it is often vulnerable to trivial memory corruption bugs.
I wonder why these network equipment manufacturers are still using CGIs in their firmware?! Is it because the MCUs they use in their hardwares are too weak to run modern version of the linux with reasonable choices to build a custom compiled version of the web server in Rust not C?Re: Netgear 0-day vulnerability analysis and exploit
#28Earlier quoted context omitted.
The last time I looked into OpenWRT/DD-WRT (years ago), it seemed disadvantageous to switch to them because they would be slower than stock firmware due to missing some kind of hardware support. Is this still the case these days? EDIT: It sounds like the situation for my router (R7000) is quite the opposite now, apparently being almost twice as fast due to new hardware acceleration features.
DD-WRT is has access to some proprietary (Broadcom?) code which enables NAT acceleration on some models which, at least in my case, greatly improved performance over OpenWRT.
"DD-WRT has a license agreement and NDA in place with Broadcom that allow usage of better, proprietary, closed source wireless drivers (binary blobs) which they are not allowed to redistribute freely."
Re: Netgear 0-day vulnerability analysis and exploit
#29Slightly off-topic: any not-made-in-china router recommendations?
Re: Netgear 0-day vulnerability analysis and exploit
#30Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.