Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

This security advisory addresses the following CVE vulnerability: CVE-2017-5679.

NETGEAR is aware of a security issue that can allow an attacker to discover a router or modem router’s administrator password by exploiting an insecure timestamp. This vulnerability only occurs when an attacker can access the internal network or when a user has turned on remote management on the router or modem router.

Remote management is turned off by default, so a user must have affirmatively turned on remote management through advanced settings for the router or modem router to be vulnerable in this manner. 

This vulnerability affects the following products:

  • D6220
  • D6300*
  • D6300B*
  • D6400
  • D8500
  • DGN2200v4*
  • R6200v1
  • R6300v1*
  • R6300v2*
  • R6400
  • R6700
  • R6900
  • R7000
  • R7100LG
  • R7300DST
  • R7900
  • R8000
  • R8300
  • R8500
  • WGR614v10*
  • WN3100RP*
  • WNDR3400v3
  • WNDR3700v3*
  • WNDR4000*
  • WNDR4500v1*
  • WNR1000v3*
  • WNR3500Lv2

Products followed by an asterisk (*) were added to the list of affected products after this advisory was first posted.

Firmware fixes are available for the following affected products:

  • D6220
  • D6300
  • D6300B
  • D6400
  • D8500
  • DGN2200v4
  • R6200v1
  • R6300v1
  • R6300v2
  • R6400
  • R6700
  • R6900
  • R7000
  • R7100LG
  • R7300DST
  • R7900
  • R8000
  • R8300
  • R8500
  • WNDR3400v3
  • WNR3500Lv2

To download the latest firmware for your NETGEAR product:

  1. Visit the NETGEAR Download Center.
  2. Under Search for, select the check box next to Firmware/Software.
  3. Start typing your model number in the search box, then select your model from the drop-down menu as soon as it appears.
    If you do not see a drop-down menu, make sure that you entered your model number correctly, or use the product drilldown to find your model.
  4. Click Release Notes under the most recent firmware version, which is the one closest to the top of the list.

Make sure that you are viewing release notes for a firmware version and not a software utility or an app. The title of the release notes page always begins with the words “Firmware Version.”

  1. Follow the instructions in the release notes to download and install the new firmware.

NETGEAR plans to release firmware updates that fix the insecure timestamp password vulnerability for all affected products.

Until a firmware fix is available for your product, NETGEAR recommends that you make sure that remote management is turned off on your router. Remote management is turned off by default. For more information, check the user manual for your product, which is available from https://www.netgear.com/support/.

The potential for password exposure remains if you do not complete all recommended steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.

NETGEAR will update this security advisory as more information becomes available.

This bug was discovered by Kevin Chung. Kevin Chung is a security engineer at Canary Connect and the author of CTFd (https://ctfd.io), a popular open source Capture The Flag framework used to educate students and train hackers. Previously, Kevin worked at Bishop Fox performing penetration testing. He graduated from NYU Poly with a degree in Computer Science after running its famous CSAW CTF for years. He maintains a technical blog at https://blog.kchung.co. You can also find him on Twitter: https://twitter.com/kchungco.


We appreciate and value having security concerns brought to our attention. NETGEAR constantly monitors for both known and unknown threats. Being pro-active rather than re-active to emerging security issues is fundamental for product support at NETGEAR.

It is NETGEAR's mission to be the innovative leader in connecting the world to the internet. To achieve this mission, we strive to earn and maintain the trust of those that use NETGEAR products for their connectivity.

To report a security vulnerability, visit https://bugcrowd.com/netgear. 

If you are a NETGEAR customer with a security-related support concern, you can contact NETGEAR customer support at techsupport.security@netgear.com. 

For all other issues, visit https://www.netgear.com/about/security/.

Last Updated:07/07/2025 | Article ID: 000037029

This article applies to:

Recently Viewed Articles

    Read this article in another language:

    Read this article in another language:

    Our team is here to help!

    Phone
    Chat
    Email