Recommended Posts

My main router is an old (and I mean REALLY old) Netgear RP614 v2, and it is not vulnerable. :huh:

Edit: Happy Birthday, Budman!!!! :punk: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint:

To those who don't get it and want the short version:

The problem is that some routers will respond to UPnP requests, wherever they're coming from. If they're coming from the LAN--no problem (unless you don't trust other machines/devices within your own LAN). If they're coming from the WAN port--then that's bad and you should disable it.

If you need more details than that, then listen to the podcast on the GRC site.

I disable it anyway. The fact that UPnP, by design, lets any application communicate with the router and open ports should make any security conscious user uneasy.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

It would allow any malicious program to actively contact your router, open whatever ports it wants, and then transmit data through those ports all without your knowledge.... pretty big security hole if you ask me.

From the inside, at which point you've already lost and UPnP isn't needed anyway

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Amped Wireless R20000G Passed! UPnP Enabled

Also mine's not on the affected devices list either!!!! Go Amped!!!!

Also mine shipped with uPnP disabled as well as WPS disabled. Extra points for them!

So is this a just rubbish. Default settings on router since I bought it and I got a pass.

I just have a forward to my web server.

Router is

Netgear DG834GT with the firmware updated to the latest.

I have an Airport Extreme router. I don't see an option for UPnP on the Airport Utility. Then again, it doesn't have many options at all.

THE EQUIPMENT AT THE TARGET IP ADDRESS

SUED OUR UPnP PROBES!

Today I had to help setup a computer for a little old lady. While I was there I ran the UPnP test. Her's failed! She had a D-link (Go figure) .... logged into the router and turned off UPnP, ran the test again and then it passed. So the rest does work!

Still not sure how people think this is suddenly new... it's been like that for a while. Didn't one of the US agencies mention this years ago?

I've always suggested to disable UPnP.

Because UPnP should NEVER be on the WAN side (internet). This means a bad guy could send a packet to your IP and if your router responds (Which is what this test is for) he could open a port in your route from the outside (Internet)

pfSense, enough said.

Not practical for the average consumer, enough said.

From the inside, at which point you've already lost and UPnP isn't needed anyway

Not from the inside, the exploit is that it responds to UPnP from the WAN side, that's the problem.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

I think your failing to understand the exploit, typically the packet is formed on the LAN side from an application, which is passed to the router, the router opens up the ports requested. The problem is here, if you are running one of the exploitable routers, ANYONE from the WAN side, can sent a correctly formed packet to your router, over the net, and your router will open the port for them. This should never be allowed on the WAN interface.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

I agree they could list their router. But we are already more than 4 pages in. So people could either flip through the pages looking to see if someone who ran the test has the same router than them, or they could just go to the site and click the button.

This thread was created not really as a list of routers affected but as away people can test themselves against the issue.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

It's so that when somebodies mother who views the computer as a magic box wants to make a Skype call with somebody, she doesn't have to reconfigure the firewall to let things pass through.

I'm running a dual stack (v4/v6) setup, and the UPnP daemon I'm running doesn't support the v6 side yet so any open ports only happen for v4 traffic. It's surprisingly annoying to track down what uses what ports to add them to the firewall.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Researchers claim Microsoft's quantum breakthrough is flawed by basic Python errors by Karthik Mudaliar Microsoft's aggressive roadmap to deliver a commercial quantum supercomputer by 2029 has now hit a bit of a snag, and it's not because of a complex sub-zero dilution refrigerator, but rather because of a few lines of basic Python code. A new critique published in the scientific journal Nature argues that simple software errors effectively manufactured the breakthrough that Microsoft's foundational research claimed back in 2025 into Majorana-based topological qubits. Topological quantum computing, the path that Microsoft chose for its research, relies on creating and controlling "Majorana zero modes." These are exotic quasiparticles that theoretically offer vastly superior error resistance compared to the highly sensitive superconducting qubits currently being championed by rivals like Google and IBM. However, physically proving you have created these particles requires sifting through massive amounts of complex electrical conductance data to isolate a specific "topological gap." Because of the sheer volume of data, physicists rely heavily on custom software pipelines to process the results. This is where the Python scripts come in. Now, according to the critique, Microsoft’s data processing software contained fundamental programming errors that ultimately skewed the published results. By mishandling data arrays or deploying incorrect logic within the Python script, the software supposedly discarded "noisy" or contradictory data. Which is why it only highlighted the specific electrical measurements that supported the topological-gap claim. The researchers behind the critique argued that this makes the findings invalid, suggesting the heralded "quantum leap" was actually a false positive generated by bad code and not a product of groundbreaking physics. However, Microsoft is pushing back hard against these allegations. The Redmond giant has formally rejected the criticism, saying that it's just a minor anomaly rather than a fatal flaw. According to the company, while there may have been a minor oversight in the data parsing scripts, it does not alter the fundamental reality of their physical experiment. Just weeks ago, Microsoft unveiled the Majorana 2 quantum processor, a milestone so significant that the company boldly accelerated its timeline for a commercial quantum supercomputer from 2035 down to 2029. But the new software allegations reopen an old wound. Microsoft's quantum division faced a remarkably similar crisis when a landmark 2018 paper on Majorana particles was famously retracted in 2021 after independent physicists discovered the data had been inappropriately cropped. That historical baggage makes the current Python-related allegations particularly sensitive. If the foundational math and data processing for the 2025 breakthrough are genuinely flawed, the highly anticipated 2029 commercial timeline could easily be delayed or, worse, cancelled.
    • Because of what they have done to VMware I will never buy anything Broadcom again.
    • AMD releases hotfix for driver install issues on Windows 10 PCs by Taras Buria Earlier this week, AMD released an important graphics driver update. Version 26.6.2 brought AMD FSR 4.1 support to the previous-gen Radeon lineup, the RX 7000 series, giving users better upscaling tech that was previously locked to the newest GPUs. However, the driver turned out to be a little buggy, with users reporting installation issues on systems still running Windows 10. AMD quickly acknowledged the bug and today released a hotfix to resolve the problem. The AMD 26.6.3 Hotfix update is now available for download from the official website. Given that it is a hotfix release, it has only one change in its release notes: AMD announced the update on its official X account and added that a WHQL driver update with the necessary fixes would be released next week. Meanwhile, users can apply the hotfix or roll back to the previous driver using the official AMD Cleanup Utility. You can download AMD Software: Adrenalin Edition 26.6.3 Hotfix Preview Driver from the official website here. It is compatible with all currently supported graphics cards and 64-bit Windows 10 and 11. Full release notes are available on the same page.
    • With Microsoft now listening to its core audience and acting upon received feedback, fans can finally expect a much better version of Windows 11 than what was available five years ago. Here is to five more years, Windows 11! I guess we all need a good laugh now and again...
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      466
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      123
    4. 4
      Michael Scrip
      82
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!