U.S. Computer Emergency Readiness Team issues security alert for Netgear R6400 and R7000 routers. US-CERT advises router owners against using their routers until a fix is made available. There’s no mitigation or workaround for the exploit, which relies on convincing router owners in accessing a URL in the form of a shortened URL. This type of vulnerability is known as a command injection, and can lead to a complete router takeover. Botnet herders have used vulnerabilities to take over Eir D1000 modems, Zyxel AMG1302 and D-Link DSL-3780 routers.
Source: https://www.bleepingcomputer.com/news/security/cert-warns-users-to-stop-using-two-netgear-router-models-due-to-security-flaw/

