Jump to content

Recommended Posts

Posted
Netgear has released a swathe of security and firmware updates for its JGS516PE Ethernet switch after researchers from NCC Group discovered 15 vulnerabilities in the device – including an unauthenticated remote code execution flaw.

The switch is vulnerable to nine high-severity vulns and a further five medium-rated ones, said NCC Group IT security consultant Manuel Ginés Rodriquez in a damning blog post about his findings.

The critical vuln, an RCE (CVE-2020-26919), came about because firmware versions prior to 2.6.0.43 "failed to correctly implement access controls in one of its endpoints, allowing unauthenticated attackers to bypass authentication and execute actions with administrator privileges."

 

https://www.theregister.com/2021/03/11/netgear_jgs516pe_switch_15_vulns/

  • Thanks 1
Posted

I bought one of these last year to use at home. It has no control or monitoring on the PoE ports despite it being a smart managed switch (a similar D-Link one I bought to replace it has), I experienced frequent dropouts on random ports and I thought the fan was quite noisy despite claims in the documentation that it was supposed to be quiet.

 

Never again.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...