Your Netgear router might be an open door for hackers

Netgear has released a security advisory addressing two critical vulnerabilities affecting Nighthawk Pro Gaming routers and certain Wi-Fi 6 access points. The company strongly recommends that users update their devices’ firmware promptly to mitigate potential risks.

The first vulnerability, identified as PSV-2023-0039, is a Remote Code Execution (RCE) flaw. This security issue allows attackers to execute arbitrary code on affected devices remotely, potentially leading to unauthorized control over the router. The second vulnerability, PSV-2021-0017, is an authentication bypass flaw, which enables attackers to circumvent authentication mechanisms and gain unauthorized access to the device’s management interface.

Recommended Videos

The affected models include Nighthawk Pro Gaming Routers such as the XR1000, XR1000v2, and XR500, as well as Wi-Fi 6 Access Points like the WAX206, WAX220, and WAX214v2.

The company has released firmware updates to address these vulnerabilities. If you do own any of the above mentioned products, it is strongly advised to download and install the latest firmware versions for your respective devices. Detailed instructions on updating firmware can be found on Netgear’s official support page.

Routers are prime targets for cyberattacks because they serve as the main gateway between the internet and home or business networks. They are always online, making them a persistent attack surface for hackers. Many routers ship with weak default security settings, including easily guessable credentials and outdated firmware, which users often neglect to update. Attackers exploit these vulnerabilities to gain control over the router, using it to monitor internet traffic, launch further attacks, or redirect users to malicious websites. Additionally, unsecured remote access features can allow hackers to take over routers from anywhere in the world.

Once compromised, routers can be used for various malicious activities, including botnet recruitment, DNS hijacking, and man-in-the-middle attacks. Hackers can exploit them to intercept sensitive data, gain access to IoT devices, and even use them as launch points for large-scale cyberattacks like DDoS attacks.

Since many users are unaware of router security risks, these devices often remain unpatched and vulnerable for extended periods. To reduce the risk, users should regularly update firmware, change default credentials, disable unnecessary remote management features, and enable strong encryption to secure their networks.

Editors’ Recommendations

  • Hackers used 30,000 computers for record-breaking DDoS attack

  • Hackers are using fake WordPress DDoS pages to launch malware

  • Europe just suffered its worst DDoS attack ever, but we don’t know why

  • Hackers just launched the largest HTTPS DDoS attack in history

  • Cloudflare just stopped one of the largest DDoS attacks ever




Related posts

Latest posts

This HP Omen gaming laptop is on sale for under $1,000

With patience, you can score a nice machine from for under $1,000. You don’t even have to do the searching yourself, as we’ve found the perfect offer for you — the HP Omen 17z gaming laptop for only $950, following a $400 discount from HP on its original price of $1,350. This device isn’t going […]

Need a new daily driver? This HP Pavilion laptop is 53% off

The HP Pavilion 16t laptop with the 13th-generation Intel Core i5 processor and 8GB of RAM is on sale for less than half-price following HP's $530 discount.

Use this code to get $50 off this 27-inch 2K gaming monitor

The 27-inch Mobile Pixels Mini-LED 2K QHD gaming monitor already offers great value at its original price of $400, but you can get it for $350 from StackSocial.

Practically all of the best Android phones are hindered by this one dumb thing

As life goes on, so might what you need from your phone. Unfortunately, you're on your own if you need

Chromecast with Google TV suffers from its long-awaited Android 14 update

Chromecast with Google TV users started reporting problems after its Android 14 update.

It’s time to say goodbye to Google Assistant as Gemini takes over

Google announced today Google Assistant will no longer be accessible on most mobile devices, in the coming months.

Google updates Find My Device with a ‘People’ tab location-sharing option

Google was spotted rolling out an update for Find My Device that brings location-sharing for people.

Apple says it will add RCS encryption to texts with Android following GSMA update

A GSMA press release announced the RCS standard will adopt encryption measures for users, Apple prepares a rollout.

CUKTECH’s 40,000mAh battery pack gives a whole new meaning to power on the go

Portable power has so many interpretations. You probably haven't seen anything like this mini 40,000mAh battery pack from CUKTECH before.

This ‘flagship-level’ and ‘exceptional’ Motorola phone is selling for a mere $250 at Amazon today

Amazon has launched a limited-time discount of 38% off the 256GB Motorola Moto G Stylus 5G, which is a solid