NETGEAR is aware of a piece of malware called VPNFilter that might target some NETGEAR devices. According to our understanding of Cisco Talos’s investigation, this malware most likely targets existing vulnerabilities for which we have already released firmware fixes.
Based on observations made by Cisco Talos and law enforcement, we believe that the following devices might be vulnerable:
- DG834
- DGN1000
- DGN2200
- DGN3500
- FVS318N
- MBRN3000
- R6400
- R7000
- R8000
- UTM50
- WNDR3700
- WNDR4000
- WNDR4300
- WNDR4300-TN
- WNR1000
- WNR2000
- WNR2200
- WNR4000
Based on this understanding, we strongly advise owners of these NETGEAR devices to take the following steps:
- Reboot your device. You can restart most devices from the device’s web browser-based management interface, or you can unplug the device, wait 15 seconds, and plug it back in.
- Make sure that you are running the latest firmware on your NETGEAR device. Firmware updates include important security fixes and upgrades.
- For more information about updating router firmware, see How do I update my NETGEAR router firmware using the Check button in the router web interface?.
- For more information about updating other device firmware, see your device’s user manual, which you can access from your product support page.
- Make sure that you have changed your default admin password.
- For more information about changing your router password, see How do I change the admin password on my NETGEAR router?.
- For more information about changing the password for other NETGEAR devices, see your device’s user manual.
- Make sure that remote management is turned off on your router. Remote management is turned off by default and can only be turned on in your router’s advanced settings.
To make sure that remote management is turned off on your router:
- On a computer that is part of your home network, type http://www.routerlogin.net in the address bar of your browser and press Enter.
- Enter your admin user name and password and click OK.
If you never changed your user name and password after setting up your router, the user name is admin and the password is password. - Click Advanced > Remote Management.
- If the check box for Turn Remote Management On is selected, clear it and click Apply to save your changes.
If the check box for Turn Remote Management On is not selected, you do not need to take any action.
To access your product support page:
- Visit NETGEAR Support.
- Start typing your model number in the search box, then select your model from the drop-down menu as soon as it appears.
If you do not see a drop-down menu, make sure that you entered your model number correctly, or select a product category to browse for your product model. - To download the latest firmware:
- Click Downloads.
- Under Current Versions, select the download whose title begins with Firmware Version.
- Click Download.
- Unzip the new firmware to an easy-to-find location, such as your desktop.
- To access your product’s user manual:
- Select User Guides and Documentation.
- Select the document whose title begins with “Reference Manual” or “User Manual.”
NETGEAR is investigating and will update this advisory as more information becomes available.
Acknowledgements
Legal Disclaimer
This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information in the document or materials linked from the document is at your own risk. NETGEAR reserves the right to change or update this document at any time. NETGEAR expects to update this document as new information becomes available.
Contact
We appreciate and value having security concerns brought to our attention. NETGEAR constantly monitors for both known and unknown threats. Being pro-active rather than re-active to emerging security issues is fundamental for product support at NETGEAR.
It is NETGEAR's mission to be the innovative leader in connecting the world to the internet. To achieve this mission, we strive to earn and maintain the trust of those that use NETGEAR products for their connectivity.
To report a security vulnerability, visit http://www.netgear.com/about/security/.
If you are a NETGEAR customer with a security-related support concern, you can contact NETGEAR customer support at techsupport.security@netgear.com.
Revision History
2018-05-23: Published advisory
2018-05-24: Added reference to Cisco Talos’s guidance
2018-05-30: Added a legal disclaimer
2018-06-06:
- Added a list of potentially affected devices
- Added a recommendation to reboot potentially affected devices
- Added instructions for accessing firmware and user manuals from a product support page