• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Unplug Your Easily Hijacked Netgear Routers Pronto

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
December 12, 2016, 7:44 PM ET
Inside Russian Internet Retailer Ulmart's Fulfillment Center As Sales Top $1b
An employee organises a stock of Netgear Inc. internet routers in the goods warehouse inside a fulfilment center operated by Ulmart, Russia's largest online electronics retailer, in Saint Petersburg, Russia, on Friday, March 7, 2014. Ulmart, the online electronics retailer backed by ex-Lenta Ltd. shareholders Dmitry Kostygin and August Meyer seeks to grow 60% this year as it expands into regions, with new product categories such as children goods, auto parts. Photographer: Andrey Rudakov/Bloomberg via Getty ImagesAndrey Rudakov—Bloomberg via Getty Images

Netgear has yet to fix a critical vulnerability uncovered by a hacker in several of its home Wi-Fi router models.

A security researcher using the online alias “Acew0rm” discovered the flaw, which allows attackers to gain complete control of affected routers with minimal effort. Last week, the researcher released the details of a simple exploit, or code that takes advantage of the vulnerability.

Acew0rm alerted Netgear to the problem on Aug. 25, but never heard back, the researcher told Fortune in a direct message on Twitter. So four months later, Acew0rm took the find public.

Netgear did not immediately reply to Fortune’s request for comment.

“Exploiting this vulnerability is trivial,” US-CERT, a cybersecurity unit within the Department of Homeland Security, warned in a bulletin on Friday. The note urged consumers to “strongly consider discontinuing use of affected devices until a fix is made available.”

Get Data Sheet, Fortune’s technology newsletter.

To take over a Netgear customer’s machine, an attacker must merely append commands, or computer instructions, to a URL being accessed by someone on an affected network. An attacker can do this by tricking a person into clicking on a malicious link or visiting a booby-trapped website that is running the exploit code.

Because the Netgear routers fail to filter out unauthorized commands, they easily succumb to an attacker’s bidding. With the correct set of instructions—for instance, opening Telnet, a channel that admits remote logins on a certain router port—the device becomes compromised.

Netgear acknowledged the problem in a brief security advisory posted Sunday. The networking equipment maker pointed to three models that are possibly vulnerable: its R7000, R6400, and R8000 routers.

The problem may be more extensive than Netgear has let on, however. Another security researcher who goes by the alias “Kalypto Pink” warned in a separate post that additional models are also open to attack.

For more on hacking, watch:

“I have tested all models below, with the exception of the R9000, and have found them to be vulnerable,” Kalypto said. The researcher listed the following routers.

  • NetGear AC1750-Smart WiFi Router (Model R6400)
  • NetGear AC1900-Nighthawk Smart WiFi Router (Model R7000)
  • NetGear AC2300-Nighthawk Smart WiFi Router with MU-MIMO (Model R7000P)
  • NetGear AC2350-Nighthawk X4 AC 2350 Dual Band WiFi Router (Model R7500)
  • NetGear AC2600-Nighthawk X4S Smart WiFi Gaming Router (Model R7800)
  • NetGear AC3200-Nighthawk AC3200 Tri-Band WiFi Router (Model R8000)
  • NetGear AC5300-AC5300 Nighthawk X8 Tri-Band WiFi Router (Model R8500)
  • NetGear AD7200-Nighthawk X10 Smart WiFi Router (R9000)

Some researchers have devised a temporary fix that involves exploiting the vulnerability itself. It’s simple, though the simplest solution is simply to switch off your router until further notice.

Here’s how the workaround works. You can block attacks simply by clicking on a version of the following link, http://[router-address]/cgi-bin/;killall$IFS’httpd’, except replace “[router-address]” with your router’s locally assigned IP address, as Bas van Shaick, a Dutch data scientist, noted on his personal blog. (For reference, here’s a primer on determining your router’s IP address.)

Clicking on that link will execute a command that disables the web server embedded in affected routers, preventing them from processing incoming commands without affecting their ability to connect to the Internet.

To see whether the workaround succeeded, simply click on a version of the following link, http://[router-address]/cgi-bin/;uname$IFS-a, except once again replace “[router-address]” with your router’s locally assigned IP address. The accessed Web page should show a error or blank page, otherwise you can assume that the fix didn’t work.

Be careful though, the workaround will last only so long as the router is not rebooted. Until the networking equipment maker pushes patches, its probably wisest for customers to unplug affected devices.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

joaquin
Commentary250 Years of Innovation
Johnson & Johnson CEO: America’s innovation advantage starts with health 
By Joaquin DuatoMay 9, 2026
2 hours ago
Qualcomm’s CEO is working with ‘pretty much all’ major AI players on top-secret devices—and powering OpenAI’s first push into hardware
AIQualcomm
Qualcomm’s CEO is working with ‘pretty much all’ major AI players on top-secret devices—and powering OpenAI’s first push into hardware
By Eva RoytburgMay 9, 2026
3 hours ago
reed
CommentaryRetirement
Tim Cook and Reed Hastings just showed every CEO how to leave gracefully
By Paul HardartMay 9, 2026
5 hours ago
Companies are abandoning ‘peanut butter’ raises as pay-for-performance takes over the workplace in the AI era
Future of WorkTech
Companies are abandoning ‘peanut butter’ raises as pay-for-performance takes over the workplace in the AI era
By Marco Quiroz-GutierrezMay 9, 2026
6 hours ago
Goldman Sachs’ tech boss says tracking individual AI usage isn’t useful. He just watches how fast his 12,000 engineers move from idea to production
AIBanks
Goldman Sachs’ tech boss says tracking individual AI usage isn’t useful. He just watches how fast his 12,000 engineers move from idea to production
By Marco Quiroz-GutierrezMay 8, 2026
19 hours ago
hacking
CybersecurityHacking
Student hackers get revenge on final exams as ‘ShinyHunters’ takes down nearly 9,000 schools study software
By Heather Hollingsworth and The Associated PressMay 8, 2026
22 hours ago

Most Popular

California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
North America
California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
By Sasha RogelbergMay 7, 2026
2 days ago
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
Magazine
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
By Sharon GoldmanMay 6, 2026
3 days ago
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
Arts & Entertainment
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
By Dave Lozo and Morning BrewMay 7, 2026
2 days ago
Current price of oil as of May 8, 2026
Personal Finance
Current price of oil as of May 8, 2026
By Joseph HostetlerMay 8, 2026
1 day ago
The CEO of Maersk, which ships 14% of everything you buy, said the Iran war is adding $500 million in monthly costs it's trying not to pass down
Energy
The CEO of Maersk, which ships 14% of everything you buy, said the Iran war is adding $500 million in monthly costs it's trying not to pass down
By Sasha RogelbergMay 8, 2026
20 hours ago
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
Success
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
By Emma BurleighMay 7, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.