Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

NETGEAR is aware of a piece of malware called VPNFilter that might target some NETGEAR devices. According to our understanding of Cisco Talos’s investigation, this malware most likely targets existing vulnerabilities for which we have already released firmware fixes.

Based on observations made by Cisco Talos and law enforcement, we believe that the following devices might be vulnerable:

  • DG834
  • DGN1000
  • DGN2200
  • DGN3500
  • FVS318N
  • MBRN3000
  • R6400
  • R7000
  • R8000
  • UTM50
  • WNDR3700
  • WNDR4000
  • WNDR4300
  • WNDR4300-TN
  • WNR1000
  • WNR2000
  • WNR2200
  • WNR4000

Based on this understanding, we strongly advise owners of these NETGEAR devices to take the following steps:

  • Reboot your device. You can restart most devices from the device’s web browser-based management interface, or you can unplug the device, wait 15 seconds, and plug it back in.
  • Make sure that you are running the latest firmware on your NETGEAR device. Firmware updates include important security fixes and upgrades.
  • Make sure that you have changed your default admin password.
  • Make sure that remote management is turned off on your router. Remote management is turned off by default and can only be turned on in your router’s advanced settings.

 

To make sure that remote management is turned off on your router:

  1. On a computer that is part of your home network, type http://www.routerlogin.net in the address bar of your browser and press Enter.
  2. Enter your admin user name and password and click OK.
    If you never changed your user name and password after setting up your router, the user name is admin and the password is password.
  3. Click Advanced > Remote Management.
  4. If the check box for Turn Remote Management On is selected, clear it and click Apply to save your changes.
    If the check box for Turn Remote Management On is not selected, you do not need to take any action.

 

To access your product support page:

  1. Visit NETGEAR Support.
  2. Start typing your model number in the search box, then select your model from the drop-down menu as soon as it appears.
    If you do not see a drop-down menu, make sure that you entered your model number correctly, or select a product category to browse for your product model.
  3. To download the latest firmware:
    1. Click Downloads.
    2. Under Current Versions, select the download whose title begins with Firmware Version.
    3. Click Download.
    4. Unzip the new firmware to an easy-to-find location, such as your desktop.
  4. To access your product’s user manual:
    1. Select User Guides and Documentation.
    2. Select the document whose title begins with “Reference Manual” or “User Manual.”
       

NETGEAR is investigating and will update this advisory as more information becomes available.

 

Acknowledgements

Cisco Talos

 

Legal Disclaimer

This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information in the document or materials linked from the document is at your own risk. NETGEAR reserves the right to change or update this document at any time. NETGEAR expects to update this document as new information becomes available.

 

Contact

We appreciate and value having security concerns brought to our attention. NETGEAR constantly monitors for both known and unknown threats. Being pro-active rather than re-active to emerging security issues is fundamental for product support at NETGEAR.

It is NETGEAR's mission to be the innovative leader in connecting the world to the internet. To achieve this mission, we strive to earn and maintain the trust of those that use NETGEAR products for their connectivity.

To report a security vulnerability, visit http://www.netgear.com/about/security/. 

If you are a NETGEAR customer with a security-related support concern, you can contact NETGEAR customer support at techsupport.security@netgear.com. 

 

Revision History

2018-05-23: Published advisory

2018-05-24: Added reference to Cisco Talos’s guidance

2018-05-30: Added a legal disclaimer

2018-06-06:

  • Added a list of potentially affected devices
  • Added a recommendation to reboot potentially affected devices
  • Added instructions for accessing firmware and user manuals from a product support page
Last Updated:07/07/2025 | Article ID: 000058814

This article applies to:

Recently Viewed Articles

    Read this article in another language:

    Read this article in another language:

    Our team is here to help!

    Phone
    Chat
    Email