Multiple flaws in Netgear Nighthawk R6700v3 router are still unpatched

by certadmin

Researchers discovered multiple high-risk vulnerabilities affecting the latest firmware version for the Netgear Nighthawk R6700v3 router.

Researchers from Tenable have discovered multiple vulnerabilities in the latest firmware version (version 1.0.4.120) of the popular Netgear Nighthawk R6700v3 WiFi router.

Netgear Nighthawk R6700v3
 

An attacker can trigger the vulnerabilities to take full control of the vulnerable devices. Below is the list of flaws discovered by the researchers:

Researchers discovered multiple instances of known vulnerable jQuery libraries (such as jquery 1.4.2), for this reason, they are urging to update them to the latest available versions.

Experts also discovered that the version of minidlna.exe running on the routers is affected by publicly known vulnerabilities. We recommend upgrading to a more recent version.

The researchers also reported that the device uses a MiniDLNA version which is known to be affected by multiple flaws.

Below is the disclosure timeline shared by Tenable:

  • September 30, 2021 – Tenable discloses to vendor.
  • October 4, 2021 – Vendor provides formal acknowledgment.
  • October 7, 2021 – Vendor requests clarification. Tenable needs more information from vendor. Vendor supplies information.
  • October 8, 2021 – Tenable provides testing suggestions.
  • October 26, 2021 – Tenable requests status update.
  • November 12, 2021 – Vendor provides status update.

The vulnerabilities affect firmware version 1.0.4.120, which is the latest release for the device.

Tenable pointed out that at the time of this writing the vulnerabilities are yet to be addressed.

“Tenable has not been informed of any available patches for these issues at the time of this writing.” states Tenable.

To read the original article:

https://securityaffairs.co/wordpress/126179/hacking/netgear-nighthawk-r6700v3-flaws.html

Top

Interdit de copier  ce contenu