Skip to content

How to find Netgear wireless routers and access points on your network

Latest Netgear vulnerabilities

Netgear has disclosed vulnerabilities in certain models of its wireless access points and WiFi routers:

  • PSV-2023-0039 is rated highly critical with a CVSS score of 9.8. Successful exploitation of this vulnerability would allow an attacker to execute arbitrary code on the vulnerable device.
  • PSV-2024-0117 is rated highly critical with a CVSS score of 9.6. Successful exploitation of this vulnerability would allow an attacker to bypass authentication and take control of the vulnerable device.

There is evidence that these vulnerabilities are being actively exploited in the wild. Note that some of the affected devices, notably the WAX206 and WAX220 wireless access points are end-of-life; the vendor has still released a security update for these devices due to the severity of the issue.

 

What is the impact?

Successful exploitation of these vulnerabilities would allow an attacker to take control of the vulnerable devices. As these devices are generally located at the network edge, they are often exposed to the public internet.

 

Are updates or workarounds available?

Netgear has released updated firmware for the affected devices. Users are urged to update as quickly as possible.

 

How do I find potentially vulnerable systems with runZero?

From the Assets Inventory, use the following query to locate systems running potentially vulnerable systems:

    hw:"XR1000" OR
    hw:"XR1000v2" OR
    hw:"XR500" OR
    hw:"WAX206" OR
    hw:"WAX220" OR
    hw:"WAX214v2" OR
    hw:"WAX2xx"

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×