Security Fixes:
- PSV-2018-0318 Weak Password Policy
- PSV-2019-0010 Cross-Site Scripting in "block site" Configuration
- PSV-2019-0012 /www/adv_index.htm Exposed Unauthenticated
- PSV-2019-0013 Cross-Site Scripting in /www/adv_index.htm
- PSV-2019-0014 Command Injection in PPPOE Functionality
- PSV-2019-0015 Cross-Site Scripting in "remote management" Configuration
- PSV-2019-0016/0018 Setup Actions Permitted Unauthenticated
- PSV-2019-0109 mini_httpd Authentication Bypass Vulnerability
- PSV-2019-0110/0184 Password Storage Information
- PSV-2019-0113 Password change & debug mode
- PSV-2019-0021 "Zombie POODLE" and "GOLDENDOODLE"
- PSV-2019-0022 Remote code execution
- PSV-2019-0192/0244 Remote code execution
- PSV-2019-0193/0245 Cross Site Scripting (XSS) in IPv6 Autoconfig settings
- PSV-2019-0170 Invalid CPE Certificate for Remote Access
- PSV-2019-0155 httpd lan_ipaddr stack overflow vulnerability
- PSV-2019-0145 httpd friendly_name stack overflow vulnerability
- PSV-2019-0124 NVRAM configuration injection caused by "SetNTP" parameter of SOAP "DeviceConfig-Set
- PSV-2019-0140 NVRAM configuration injection caused by "New5GCTSRTSThreshold" parameter of SOAP "WLANConfiguration-SetAdvancedW
- PSV-2019-0141 NVRAM configuration injection caused by "NewCTSRTSThreshold" parameter of SOAP "WLAN
For more information about security vulnerabilities, visit https://www.netgear.com/about/security.
Download Link: http://www.downloads.netgear.com/files/GDC/D7000/D7000_FW_V1.0.1.78_1.0.1.zip
Firmware Update Instructions:
To update your product’s firmware, follow the instructions in your product’s user manual. To find your user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.