A recent flaw has been discovered in multiple Netgear router models, reportedly allowing hackers to bypass administrator authentication and gain full access to the device as found by Network engineer, Peter Adkins.
Adkins discovered that routers in the popular Netgear 'WNDR' range are running a Simple Object Access Protocol (SOAP) service as part of the Netgear Genie device administration application. Seemingly secure, he was able to bypass filtering and authentication for the SOAP service over a Wi-Fi connection without much effort.
Once the connection had been established, Adkins was able to extract the admin password, Wi-Fi interface credentials, station identifiers, the device serial number and even information on connected clients. He then notified Netgear of this security issue, however was met with a response which included "the network should still stay secure" - apparently due to hidden built-in security features.
If you wish to view more in-depth information about this vulnerability, Adkins has released an analysis on Github. We'll also list below exactly what routers have been tested and confirmed to contain this issue.
Confirmed vulnerable routers:
- NetGear WNDR3700v4 - V126.96.36.199SH
- NetGear WNDR3700v4 - V188.8.131.52
- NetGear WNR2200 - V184.108.40.206
- NetGear WNR2500 - V220.127.116.11
- NetGear WNDR3700v2 - V18.104.22.168
- NetGear WNDR3700v1 - V22.214.171.124
- NetGear WNDR3700v1 - V126.96.36.199
- NetGear WNDR4300 - V188.8.131.52
Routers believed to be vulnerable but not yet tested: