8 ms·
Netgear 0-day vulnerability analysis and exploit
- mobilio 6y agoIt's another reason once you bought a router to reflash it with alternative firmwares as OpenWRT or DD-WRT
- wycy 6y agoThe last time I looked into OpenWRT/DD-WRT (years ago), it seemed disadvantageous to switch to them because they would be slower than stock firmware due to missing some kind of hardware support. Is this still the case these days? EDIT: It sounds like the situation for my router (R7000) is quite the opposite now, apparently being almost twice as fast due to new hardware acceleration features.
- mushufasa 6y agoIt's faster in my scenario. YMMMV.
- msla 6y agoNot in the specific models I looked at. I personally use a Linksys WRT3200ACM. https://openwrt.org/toh/linksys/linksys_wrt3200acm https://openwrt.org/toh/linksys/linksys_wrt3200acm
- zantana 6y agoDD-WRT is has access to some proprietary (Broadcom?) code which enables NAT acceleration on some models which, at least in my case, greatly improved performance over OpenWRT.
- mobilio 6y agoExactly. They have signed an NDA with Broadcom: https://openwrt.org/meta/infobox/broadcom_wifi https://openwrt.org/meta/infobox/broadcom_wifi "DD-WRT has a license agreement and NDA in place with Broadcom that allow usage of better, proprietary, closed source wireless drivers (binary blobs) which they are not allowed to redistribute freely."
- rmrfstar 6y agoWhat's the deal with no signatures on OpenWRT firmware images.
- yjftsjthsd-h 6y ago? https://openwrt.org/docs/guide-user/security/release_signatures https://openwrt.org/docs/guide-user/security/release_signatu...
- jaboutboul 6y agoWow. This is gonna be bad.
- mmm_grayons 6y agoRouters have been full of stupidly bad bugs for years; nothing really new here. I recall analyzing one a while back and finding that it used session tokens to determine whether one was logged into the interface. These were derived from the uptime with triple des, but the nonce was a constant string of text and the key was based off of interface mac addresses. One has to wonder, at that point, why do anything at all?
- yjftsjthsd-h 6y ago> One has to wonder, at that point, why do anything at all? Still prevents the most casual attacks; obscurity is sorta technically better than nothing. (Or worse, of course, if it gives the incorrect appearance of actual security...)
- stragies 6y agoTreat these devices like PCs: See the installed system as "example installation to demonstrate functioning". Like HP with the bundled Crapware on PCs. Just install OpenWrt as soon as you did a basic function test. And only buy hardware you know to be compatible.
- Namidairo 6y agoThe problem with than plan however, is that many of these devices tend to depend on arcane network hardware acceleration features in order to reach decent switching throughput. Which rules out OpenWrt on some of the lower-spec pieces if you have a faster WAN connection (Ie. 1gbit), as I don't believe they have support for these on many platforms. (MT7621 is referenced as supported, and Qualcomm's "SFE" being supported in community builds)
- g-b-r 6y ago> Which rules out OpenWrt on some of the lower-spec pieces it's ruled out in any case as of now, because the current releases require (or at least strongly recommend) 64 MB of RAM, which surprisingly in 2020 is a problem in the networking world (for the cheapest -under 70$- devices)
- rubatuga 6y agoOpenwrt on Mt7621 is phasing out hardware accelerated NAT
- philjohn 6y agoQualcomm SFE has been replaced in OpenWRT with the more generic "flow offload", on an R7800 you can get gigabit speeds lan to wan. Wireless is still lagging as the IPQ8064 has two NSS packet processing cores which, amongst other things, also accelerate crypto, including WPA. I've got an R7800 running router duties on OpenWRT and then a Netgear Orbi RBK50 set running in AP mode which works well for my needs. There IS a community effort to port the NSS acceleration (which accelerates qdisc and therefore traffic shaping with SQM) from the QSDK sources, but it's slow going.
- JeremyNT 6y ago
- Sodman 6y agoThe worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability fixes, but it basically rendered the router unusable. It would crash every few hours with normal usage. I googled around and turns out it was a known issue, the only recommended fix was "roll back to version x.x.x (2 versions prior). I found this fix months after it had been posted, and there had still been no new patch released to fix the issue. When my relatives call me to fix their wifi, I now have to think twice about updating the firmware. These days I recommend the google wifi mesh router(s), because they just involve the least maintenance effort. They have less fine-tune controls and the wifi speed is slightly slower when you start approaching gigabit speeds (vs other high-end consumer routers), but it's definitely worth the trade off for me. Plus, anyone calling me to help with their wifi won't notice either of those things :)
- tw04 6y agoHighly recommend the synology line of routers. I've deployed a few of them for neighbors and have gotten exactly 0 calls. They mesh over wired or wireless, and for all of their faults Synology does a pretty good job of releasing software updates for their products for WAY longer than any other vendor I've worked with. Just make sure you use the 2600AC as the primary router, the 2200s can technically function in that role but are pretty under-powered.
- clairegraham 6y agoDoes the 2600 allow you to set a static DFS channel? It looks like it might support an auto-switch mode but I can’t find anything specific.
- ThePowerOfFuet 6y ago>static DFS channel This is a contradiction. The whole point of DFS is "if you detect radar on this frequency you must stop transmitting on it". This is typically followed by a change of channel to avoid an outage of the Wi-Fi, hence "dynamic frequency selection".
- alyandon 6y agoReading stuff like this makes me glad I ditched consumer grade all-in-one stuff and went with a $REAL (feel free to substitute appropriate brand) router and stand alone AP.
- jasondclinton 6y agoThat's not a workable solution for the vast majority of the population.
- alyandon 6y agoSadly not. You generally have to be very technically inclined to use something like Mikrotik (which is what I'm using) and even the Ubiquiti stuff isn't as easy to use as it could be.
- garaetjjte 6y agoMaybe better than typical SOHO, but I have been disappointed with Mikrotik stuff as well.
- alyandon 6y agoMy RB3011 has been pretty much rock solid for me. If you don't mind me asking - what kinds of issues have you run into?
- garaetjjte 6y agoWireless performance isn't great (20$ clunky china routers are usually faster), SXTsq that always slowed down horribly after few weeks of uptime, hAP Lite firmware that died (had to be reflashed from netboot, config gone), many software problems with SXT LTE6 (stopped working after upgrade, still broken after downgrade, mysteriously after hour of flashing various versions it suddenly started working again. Incoming voice call to modem SIM card just breaks connection, and it never fixes itself automatically, you need to manually down/up interface. I now fear touching anything in this installation at all).
- Namidairo 6y agoI noticed there's a gap in some of the affected lists. (Mainly the MediaTek/Ralink mipsel hardware) They don't appear to have the same httpd binary talked about here. (Instead they have a mini_httpd?) They do appear however to be still very vulnerable to CVE-2020-8597 (no PIE or stack cookies, probably RWX stack) and for the one device I took a look at (R6700v2), the firmware image hasn't been updated since last September. Oh well.
- hathym 6y agoWhy is this a big deal since you can exploit the vulnerability only when you are connected to the local network? (I've seen some of these exploits used to replace the installed firmware with openwrt)
- cjbprime 6y agoIn general, this is not a safe assumption to make -- for example, due to DNS Rebinding attacks. The article also mentions that the exploit is working remotely: > As the vulnerability occurs before the Cross-Site Request Forgery (CSRF) token is checked, this exploit can also be served via a CSRF attack. If a user with a vulnerable router browses to a malicious website, that website could exploit the user’s router. The developed exploit demonstrates this ability by serving an html page which sends an AJAX request containing the exploit to the target device. Also, if you're replacing the firmware, the new firmware can create an outgoing root shell to a destination of your choice. There's no internal limitation here.
- AdmiralAsshat 6y agohttps://github.com/grimm-co/NotQuite0DayFriday/blob/master/2020.06.15-netgear/notes.txt https://github.com/grimm-co/NotQuite0DayFriday/blob/master/2... >* R6300v2 version 1.0.3.6CH, 1.0.3.8, and 1.0.4.32 >* R6400 version 1.0.1.20, 1.0.1.36, and 1.0.1.44 >* R7000 versions 9.88, 9.64, 9.60, 9.42, 9.34, 9.18, 9.14, 9.12, 9.10, 9.6, and 8.34 Strange, my Netgear R6700 is not on the list. Does that mean it's unaffected, or they simply didn't have that model on hand to test against?
- Namidairo 6y agoThere is a much longer list within the comments of exploit.py It appears they may have scraped the Netgear site and run all the images through binwalk + objdump to make the list.
- abc-xyz 6y agoSlightly off-topic: any not-made-in-china router recommendations?
- mobilio 6y agoMikrotik
- g-b-r 6y agoThey are made in china, at least the last I bought (at least the company and the software are not chinese, of course)
- mobilio 6y agoYes, but OS (firmware) is built in EU. Technically someone somewhere make a electronic plate and sold some elements on it. But difference is who is wrote a software on top.
- g-b-r 6y ago? Who wrote a software (and designed and sold the whole thing) is some difference, much better than nothing, but the "electronic plate" can still be filled with backdoors and other gimmicks...
- jankiehodgpodge 6y agoDraytek
- g-b-r 6y agoAVM, I think (but not sure) that they're still made in Germany
- devy 6y agoIn SOHO devices like the R7000, the web server must parse user input from the network and run complex CGI functions that use that input. Furthermore, the web server is written in C and has had very little testing, and thus it is often vulnerable to trivial memory corruption bugs. I wonder why these network equipment manufacturers are still using CGIs in their firmware?! Is it because the MCUs they use in their hardwares are too weak to run modern version of the linux with reasonable choices to build a custom compiled version of the web server in Rust not C?
- icedchai 6y agoRust isn't magic. And you can write CGIs in any language. Shouldn't we also ask why are they using their own web server? or why a company with millions of devices deployed has done little testing?
- devy 6y ago> Rust isn't magic. Let's not going to that debate. It's a good start to improve security postures, regardless how you spin it. But more importantly, my point is why are they doing CGI at all?
- icedchai 6y agoThere is nothing wrong with CGI. It's simply a standard to forward a request from a web server to another application using environment variables and stdio. Generally, you want your router routing, not wasting CPU and memory running admin applications that are used less than once a month.
- fomine3 6y agoCGI is still great environment for simple webapp on embedded device. Using Rust is normally overkill and increases complexity. Python/PHP should be enough. BTW quality of embedded webappa is mostly sucks.
- user5994461 6y agoThey're running CGI and writing homemade web servers in C because they haven't maintained or upgraded their software in decades. I don't think they are low power devices. My bet would be they're relatively normal hardware running a light linux. It takes quite a bit of power to route gigabit ethernet or ac wifi.
- Meekro 6y agoI've used Apple routers for many years, but since they've been discontinued I wonder what I'll do when I need to replace them. All the major alternatives seem to have crap software that requires frequent reboots and has security issues. Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.
- beamatronic 6y agoEero
- post_break 6y agoI almost went full Unifi, got lazy and got Eero. So far everything has been fantastic. It's not perfect but it works and delivered on its promise. Speed is fast, it's not Wifi 6 but neither are any of my devices. Paid full price too, not a shill here.
- WorldMaker 6y agoUbiquiti has a consumer/prosumer brand called Amplifi now. It's got the ease of something like Eero but the decade of experience of Unifi. (They also already have a WiFi 6 mesh router at the top of the line on the prosumer side.)
- hedora 6y agoI recommended an Amplifi to some friends that aren’t computer-savvy, and didn’t hear back. (Their previous router was crashing frequently.) I visited them a few months later and noticed it, so I asked about it. They had kind of forgotten about it. There were zero problems setting it up and zero problems since. They said they thought it was kind of pricey. If I remember right, it was $50 more than the cheapest (but terrible) one with similar specs. It was $100 less than an expensive, terrible and comparable one. I can’t imagine a more favorable review of consumer networking gear. :-) Also, I have had zero issues with the Ubiquiti access point I use at home. I have a pcengines apu2 OpenBSD router, so I can’t say much about their routers.
- 0fcf8d3559a64c 6y agoI am sick of having to assume my network hardware is trivially compromised. What will it take for me to be able to purchase a microkernel driven router/access-point with audited drivers (or Rust based)? I would settle for mediocre performance (ie no gigabit) if I could have some strong security guarantees. Can I setup Redox or seL4 as home network hardware at this point? Or would the pain threshold still be quite high?
- hpkuarg 6y agoI run an OpenBSD router at home. I'm not sure if that would satisfy your security requirements.
- dehrmann 6y ago> I am sick of having to assume my network hardware is trivially compromised. I don't have the gateway my ISP gave me on my LAN for this reason. I do have to laugh a little bit about people who use a VPN to hide requests (DNS? Because most of the web is HTTPS, now) from their ISP when their ISP has a device on their network.
- WorldMaker 6y agoEven personally owned hardware has its risks from today's ISPs. DOCSIS standards require every off the shelf cable modem to basically have giant "management" back doors for the ISPs. They can remotely install firmware updates to your modem that you own for "your safety" and there's not much you can do about it.
- theincredulousk 6y agoGet an enterprise router/firewall. Also most of these vulnerabilities (as the article points out) are in the web server. If the web server isn't exposed,it isn't of much practical security concern. I've also run DD-WRT for years with excellent results. Per the usual benefits of open source and active maintainers, it is generally going to (a) have the trivial stuff already addressed (b) keep up to a reasonable extent with security patches.
- 1024core 6y agoIs Netgear the new Adobe (see: Flash) ?
- theincredulousk 6y agoPredictably, the web servers are an afterthought for branding so that users don't have to edit configuration files and operate at a command line. (a) 99%+ of people buying these things do not know or care about security, aside from someone stealing their WiFi bandwidth (b) the manufacturer does not care because of (a). As follows, all they care about (WRT to the web server) is that they are easy enough for non-technical people to setup such that they don't end up on a tech support call or returning the device for a refund. That is it. If you are the 1% that cares about security on your home network, it is far less stressful to simply conclude these products are not for you and move on with your life. You should be looking at enterprise hardware, open source router firmware, or rolling your own. In any case, what surprises me is that over time the router manufacturers haven't simply built up a single, relatively patched-up, web server implementation that they re-use. Even without aligned incentives, you would think over years and years of development they'd have something at least as good as what you can clone out from from github for free.
- esaym 6y agoI gave up on netgear long ago for access points. Been running stuff from https://mikrotik.com/ https://mikrotik.com/ since 2016. They are a bit dated in some areas, but they are cheap and I've never had any issues.
- DiabloD3 6y agoIm surprised no one has made the semi-obligitory "buy Ubiquiti Edgerouter X/Lite and throw in a NanoHD" comment.
- rdudek 6y agoAs someone who recently got the Dream Machine Pro with NanoHD access point, most of the consumers will not want to deal with such a setup. Also, Ubiquiti has their own issues to sort out as well.
- ThePowerOfFuet 6y ago>Also, Ubiquiti has their own issues to sort out as well. I also own a UDM Pro, and this is an understatement.
- joemazerino 6y agoReports of 0days always make me consider projects like OpenWRT and Tomato. I wonder how fast a non profit project can patch compared to OEMS.
- deleted 6y ago[deleted]
- aVx1uyD5pYWW 6y agoIs there any mitigation for this? AFAICT netgear has not released a patched firmware for this bug yet. Anything else that can be done?