NETGEAR is aware of a security vulnerability that could allow an attacker on the local area network to access an insecure preview image in a ReadyNAS OS 6 system’s Admin Page and execute commands through it, including changing the administrator password.
This vulnerability can only be exploited from within the local area network.
This vulnerability affects the following products:
- All ReadyNAS storage systems running OS 6.x
NETGEAR released a firmware update, ReadyNAS OS 6.7.1, that fixes the local command injection vulnerability for all affected products. NETGEAR strongly recommends that all affected users install the latest firmware for their ReadyNAS system as soon as possible. For instructions, see ReadyNAS OS 6: Updating Firmware.
The potential for local command injection remains if you do not update your firmware to ReadyNAS OS 6.7.1 or later. NETGEAR is not responsible for any consequences that could have been avoided by updating your firmware as recommended in this notification.
We appreciate and value having security concerns brought to our attention. NETGEAR constantly monitors for both known and unknown threats. Being proactive rather than reactive to emerging security issues is fundamental for product support at NETGEAR.
It is NETGEAR's mission to be the innovative leader in connecting the world to the internet. To achieve this mission, we strive to earn and maintain the trust of those that use NETGEAR products for their connectivity.
To report a security vulnerability, visit https://bugcrowd.com/netgear.
If you are a NETGEAR customer with a security-related support concern, you can contact NETGEAR customer support at techsupport.security@netgear.com.
For all other issues, visit http://www.netgear.com/about/security/.