Recommended Posts

My main router is an old (and I mean REALLY old) Netgear RP614 v2, and it is not vulnerable. :huh:

Edit: Happy Birthday, Budman!!!! :punk: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint:

To those who don't get it and want the short version:

The problem is that some routers will respond to UPnP requests, wherever they're coming from. If they're coming from the LAN--no problem (unless you don't trust other machines/devices within your own LAN). If they're coming from the WAN port--then that's bad and you should disable it.

If you need more details than that, then listen to the podcast on the GRC site.

I disable it anyway. The fact that UPnP, by design, lets any application communicate with the router and open ports should make any security conscious user uneasy.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

It would allow any malicious program to actively contact your router, open whatever ports it wants, and then transmit data through those ports all without your knowledge.... pretty big security hole if you ask me.

From the inside, at which point you've already lost and UPnP isn't needed anyway

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Amped Wireless R20000G Passed! UPnP Enabled

Also mine's not on the affected devices list either!!!! Go Amped!!!!

Also mine shipped with uPnP disabled as well as WPS disabled. Extra points for them!

So is this a just rubbish. Default settings on router since I bought it and I got a pass.

I just have a forward to my web server.

Router is

Netgear DG834GT with the firmware updated to the latest.

I have an Airport Extreme router. I don't see an option for UPnP on the Airport Utility. Then again, it doesn't have many options at all.

THE EQUIPMENT AT THE TARGET IP ADDRESS

SUED OUR UPnP PROBES!

Today I had to help setup a computer for a little old lady. While I was there I ran the UPnP test. Her's failed! She had a D-link (Go figure) .... logged into the router and turned off UPnP, ran the test again and then it passed. So the rest does work!

Still not sure how people think this is suddenly new... it's been like that for a while. Didn't one of the US agencies mention this years ago?

I've always suggested to disable UPnP.

Because UPnP should NEVER be on the WAN side (internet). This means a bad guy could send a packet to your IP and if your router responds (Which is what this test is for) he could open a port in your route from the outside (Internet)

pfSense, enough said.

Not practical for the average consumer, enough said.

From the inside, at which point you've already lost and UPnP isn't needed anyway

Not from the inside, the exploit is that it responds to UPnP from the WAN side, that's the problem.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

I think your failing to understand the exploit, typically the packet is formed on the LAN side from an application, which is passed to the router, the router opens up the ports requested. The problem is here, if you are running one of the exploitable routers, ANYONE from the WAN side, can sent a correctly formed packet to your router, over the net, and your router will open the port for them. This should never be allowed on the WAN interface.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

I agree they could list their router. But we are already more than 4 pages in. So people could either flip through the pages looking to see if someone who ran the test has the same router than them, or they could just go to the site and click the button.

This thread was created not really as a list of routers affected but as away people can test themselves against the issue.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

It's so that when somebodies mother who views the computer as a magic box wants to make a Skype call with somebody, she doesn't have to reconfigure the firewall to let things pass through.

I'm running a dual stack (v4/v6) setup, and the UPnP daemon I'm running doesn't support the v6 side yet so any open ports only happen for v4 traffic. It's surprisingly annoying to track down what uses what ports to add them to the firewall.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Surprise Execs are dumb. I hope the rehired engineers said were not coming back until we get 2x our salary.
    • Ford execs say they made a mistake when they replaced human engineers with AI by David Uzondu Ford recently announced that over the last three years, it's had to rehire about 350 "gray beard" engineers to mentor younger staff and reprogram diagnostic systems and AI tools that were failing to meet up to quality expectations. The company's VP of vehicle hardware engineering, Charles **** said that leaders overlooked the deep experience of veterans who survived many product cycles. **** admitted that simply replacing them with AI was a huge mistake, and that while AI is "a fantastic tool," it remains "only as good as the information you use to train it." The rehired engineers now run mandatory meetings to troubleshoot vehicles and reprogram automated engineering software and AI tools to prevent glitches before production. These technical specialists hunt for failure points before parts ever reach the plant floor, helping prevent the massive recalls and defects that previously cost the company billions as it aims to cut one billion dollars in expenses this year. In last year's JD Power Quality Survey, an annual study that measures the quality of a car during the first three months of ownership, Ford finished 10th among mainstream brands and scored below the industry average. But this year, JD Power ranked the automaker as the top mainstream brand, placing it above the likes of Toyota Motor Corp. and Honda Motor Co. Ford attributed this massive improvement directly to the expertise of these returned engineers. Ford's realization that AI cannot magically design and test quality vehicles without senior human oversight is just the tip of the iceberg. When Careerminds looked at companies that conducted AI-driven layoffs, researchers found out that 35.6% of those companies had to rehire more than half of the employees they previously fired. Another 32.7% had to rehire between 25% and 50% of them. In 2024, Sebastian Siemiatkowski, CEO of Klarna, proudly announced that its new chatbot was doing the work of 700 full-time customer service agents. As a result, the fintech company froze hiring and cut hundreds of positions. But by mid 2025, and into 2026, Klarna was scrambling to recruit human agents again because customer satisfaction had plummeted. It turns out, while AI is very good at answering basic questions like how to check an account balance, when faced with complex customer issues that require nuance, the thing usually resorts to the unhelpful, robotic corporate jargon we all know and love.
    • Free AI in IDEs is shifting to paid models Or you know, you could just learn to actually design and code apps, use frameworks to handle the repetitive parts and not use AI at all - and voila... free for life!
    • In a sane world US antitrust laws wouldn't even allow these companies to be in the position to be subjected to EU directives. As you say, better than oligarch nothing.
    • Apple reportedly has a second-generation iPhone Fold planned for 2027 Good grief, Apple hasn't even released a first folding phone and the Apple faithful is already obsessing over the sequel? Seriously people, go out and touch grass... because this level of obsession is borderline stalkery/neurotic.
  • Recent Achievements

    • Week One Done
      xvvxcvv earned a badge
      Week One Done
    • One Month Later
      xvvxcvv earned a badge
      One Month Later
    • Enthusiast
      Xonos went up a rank
      Enthusiast
    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      129
    4. 4
      neufuse
      69
    5. 5
      Xenon
      68
  • Tell a friend

    Love Neowin? Tell a friend!