ISC StormCast for Thursday, December 1st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 December 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, December 1st, 2022 edition of the Sands and the Stormsendors Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | I just posted a little bit unusual diary. |
| 0:17.7 | We published this newsletter once a week, the At Risk newsletter, and I'm looking at |
| 0:22.6 | different vulnerabilities. I found something odd this week, looking at sort of last week's |
| 0:28.2 | vulnerability. There are 20 war on abilities that were released in Netgear and D-Link |
| 0:34.2 | routers. For Netgear, it affects the R7,000P router, different firmware versions, and for D-Link, |
| 0:42.6 | it's a number of different devices that are affected, also again, a number of different |
| 0:48.4 | firmware versions here. |
| 0:51.1 | Problem is, there isn't really anything on the vendor's website about |
| 0:55.6 | any patches for it. DeLinks security site actually stops about two years ago. December 2020, |
| 1:04.5 | I guess they had no vulnerabilities, at least they had no updates, maybe. Since then, Netgear had |
| 1:10.3 | some updates, but nothing really |
| 1:11.6 | related to this particular model recently. So not 100% sure what's going on here. All of these |
| 1:18.1 | vulnerabilities appear to have been reported by the same individual, and there is a GitHub |
| 1:23.4 | repository with proof-of- of concept exploits. |
| 1:31.4 | The vulnerabilities do appear to affect pretty much the admin interface. |
| 1:35.2 | So it's these typical web application vulnerabilities as far as I can tell, |
| 1:39.4 | based on the brief description in the National Vulnerablellies database. |
| 1:47.0 | I'll leave it up to you, what to do here, but as usual, don't expose the admin interface, and then be on the lookout for any updates coming down the pipe from Netgear and D-Link. |
| 1:57.0 | And talking about mystery updates, Apple today also released an update for iOS. |
| 2:03.6 | And now it does fix some bugs. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

