Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
NETGEAR

NETGEAR Vendor Cyber Rating & Cyber Score

netgear.com

We turn ideas into innovative networking products that connect people, power businesses, and advance the way we live. For Home NETGEAR makes it easy for you to have the smartest home in the neighborhood, with the latest, fastest networking technology products. From the most advanced wireless internet connectivity, to superior streaming, remote home video monitoring, and storage solutions, your home networking system will have the speed, range and performance you need, every time you need it. At NETGEAR, we focus on all things connected, with the goal of making your online experience seamless so you can sit back, relax and do more. For Business In business, confidence is everything. When it comes to your network, it’s even more


NETGEAR A.I CyberSecurity Scoring

NETGEAR
Company Information
Website:http://www.netgear.com
Employees number:1,420
Number of followers:70,522
NAICS:5112
Industry Type:Software Development
Homepage:netgear.com
NETGEAR Risk Score (AI oriented)
Between 700 and 749
logo
NETGEARSoftware Development
Updated:
17/08/2026
718/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
NETGEAR Global Score (TPRM)
xxxx
logo
NETGEARSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

NETGEAR
NETGEARModerate
Current Score
718Ba (MODERATE)
01000
5 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
718Before Incident
JULY 2026
721Before Incident
Vulnerability
01 Jul 2026NETGEAR
NETGEAR, Tenda, Alcatel, Mitsubishi Electric and D-Link: Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft

New Linux Botnet Evooo1Bot Emerges, Targeting Edge Devices for DDoS and Cybercrime

716After Incident
CRITICAL-5
NETALCTENMITDLI1786947932
New Linux Botnet Evooo1Bot Emerges, Targeting Edge Devices for DDoS and Cybercrime FortiGuard Labs has identified a previously unknown Linux botnet, Evooo1Bot, named after the "evooo1" string embedded in its malware samples. Active since July 2026, the botnet compromises internet-facing routers, firewalls, cameras, and other edge devices, repurposing them for DDoS attacks, SOCKS5 proxy relays, credential theft, and network intrusion. ### Capabilities and Tactics Evooo1Bot builds on the Mirai source code but expands its functionality with: - Encrypted C2 communication (AES, ChaCha20, XOR) - SSH brute-forcing, traffic sniffing, and remote shell access - Exploit modules targeting vulnerabilities in Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link devices - Anti-analysis checks for debugging tools (GDB, Wireshark), sandboxes, and virtual environments - Persistence mechanisms, including fake systemd services, cron jobs, and shell-profile modifications The malware downloads payloads from 91.92.40[.]118/wget.sh, which detects the target’s CPU architecture before executing the appropriate binary. It also clears Bash history to erase traces of infection. ### Operational Impact Evooo1Bot communicates over TCP port 443, blending into legitimate HTTPS traffic. Its C2 infrastructure supports remote commands for system reconnaissance, file transfers, and interactive shell access, while its persistence module ensures survival across reboots. Operators appear to track infection success by vulnerability and device type, suggesting a structured campaign. The botnet’s multi-layered encryption and evasion techniques make detection and analysis challenging. ### Indicators of Compromise (IOCs) - C2/Payload Server: 91.92.40[.]118 - Loader URL: http://91.92.40[.]118/wget.sh The discovery highlights the growing threat of botnets targeting unpatched edge devices, underscoring the need for robust network security measures.
INCIDENT DETAILS -
TYPE
BotnetDDoSCybercrime
MOTIVATION
Financial gainNetwork intrusionData exfiltration
IMPACT
CredentialsRoutersFirewallsCamerasEdge devicesOperational Impact: Repurposed devices for DDoS attacks, SOCKS5 proxy relays, and network intrusion
DATA BREACH
CredentialsData Exfiltration: Yes
JUNE 2026
721Before Incident
MAY 2026
721Before Incident
APRIL 2026
719Before Incident
MARCH 2026
719Before Incident
FEBRUARY 2026
722Before Incident
Vulnerability
26 Feb 2026NETGEAR
Tenda, TP-Link and Netgear: Researchers discover massive Wi-Fi vulnerability affecting multiple access points — AirSnitch lets attackers on the same network intercept data and launch machine-in-the-middle attacks

AirSnitch: Wi-Fi Vulnerability Exploiting Network Stack Weaknesses

717After Incident
CRITICAL-5
TENTP-NET1772144683
Researchers Uncover Wi-Fi Vulnerability "AirSnitch" Exploiting Network Stack Weaknesses A team of researchers from the University of California, Riverside, has identified a critical flaw in Wi-Fi security dubbed AirSnitch, which allows attackers to intercept network traffic even on networks with client isolation enabled. The vulnerability exploits gaps in how Wi-Fi links MAC addresses, encryption keys, and IP addresses across network layers (1, 2, and 3), enabling attackers to impersonate devices and reroute traffic. Lead researcher Xin’an Zhou warned that AirSnitch "breaks worldwide Wi-Fi encryption" and could facilitate advanced attacks, including cookie theft, DNS poisoning, and cache manipulation, by effectively wiretapping the network. Unlike traditional exploits, AirSnitch does not crack encryption but instead undermines the assumption that encrypted clients are fully isolated from one another. The attack leverages four primary methods to bypass client isolation: 1. Shared Key Abuse – Exploiting the Group Temporal Key (GTK) used in most networks to broadcast malicious packets disguised as legitimate traffic. 2. Gateway Bouncing – Sending data to an access point addressed to a gateway MAC, tricking the gateway into forwarding it to the victim. 3. MAC Spoofing (Downlink) – Mimicking a victim’s MAC address to intercept their incoming traffic. 4. MAC Spoofing (Uplink) – Impersonating backend devices (e.g., gateways) to capture outgoing traffic from a target. The vulnerability was confirmed across five consumer routers (Netgear Nighthawk x6 R8000, Tenda RX2 Pro, D-LINK DIR-3040, TP-Link Archer AXE75, Asus RT-AX57), two open-source firmwares (DD-WRT v3.0-r44715, OpenWrt 24.10), and two university enterprise networks, indicating the flaw is inherent to Wi-Fi architecture rather than specific hardware. While the attack is complex, researchers emphasize that the findings highlight systemic weaknesses in Wi-Fi security, urging manufacturers and standards bodies to address these flaws in future protocols. The discovery underscores the need for stronger client isolation mechanisms to prevent such exploits.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Network traffic interception, cookie theft, DNS poisoning, cache manipulationSystems Affected: Wi-Fi networks with client isolation enabledOperational Impact: Potential unauthorized access to sensitive data and network trafficIdentity Theft Risk: High (due to cookie theft and traffic interception)
DATA BREACH
Type Of Data Compromised: Network traffic, cookies, DNS cacheSensitivity Of Data: High (potential PII, session tokens)Data Encryption: Bypassed (not cracked)Personally Identifiable Information: Potential (cookies, session data)
JANUARY 2026
721Before Incident
DECEMBER 2025
720Before Incident
NOVEMBER 2025
719Before Incident
OCTOBER 2025
718Before Incident
SEPTEMBER 2025
717Before Incident
JULY 2025
735Before Incident
Cyber Attack
30 Jul 2025NETGEAR
Netgear and D-Link: Masjesu Botnet Targets Routers and Gateways For Paid DDoS Attacks

Masjesu Botnet: A Stealthy, Evolving IoT Threat for DDoS-as-a-Service

715After Incident
HIGH-20
DLINET1775644215
Masjesu Botnet: A Stealthy, Evolving IoT Threat for DDoS-as-a-Service The Masjesu botnet, first detected in early 2023 and still active through 2026, has established itself as a highly sophisticated DDoS-for-hire service targeting Internet of Things (IoT) devices. Unlike traditional botnets that rely on large-scale, noisy infections, Masjesu prioritizes stealth and long-term persistence, avoiding high-profile networks like U.S. Department of Defense systems to evade detection and legal action. ### Stealth Tactics & Operational Methods Masjesu employs advanced evasion techniques to bypass security measures, including: - XOR-based encryption to conceal command-and-control (C2) domains and payloads, decrypting them only at runtime. - Hardened persistence by binding to a hardcoded TCP port and ignoring termination signals. - Process masquerading, renaming its executable to mimic legitimate system files (e.g., a Linux dynamic linker) and using cron jobs to re-execute every 15 minutes. ### Exploitation & Propagation The botnet spreads by scanning random IP addresses for vulnerable open ports, targeting devices from manufacturers like D-Link, Netgear, Huawei, and GPON. Upon exploitation, it deploys a malicious shell script to recruit devices into its network. Once integrated, bots receive instructions to launch DDoS attacks under a unique "masjesu" user-agent. ### Defensive Measures & Impact Due to its obfuscation-heavy approach, traditional antivirus detection is often ineffective. Organizations are advised to: - Monitor outbound traffic for unusual HTTP requests or connections to known malicious domains. - Implement process and file integrity monitoring to detect spoofed system files or unauthorized cron jobs. - Enforce basic IoT security hygiene, including changing default credentials and applying firmware updates to patch known vulnerabilities. Masjesu’s commercial DDoS-for-hire model and low-profile operations make it a persistent threat, underscoring the need for behavior-based defenses in IoT security.
INCIDENT DETAILS -
TYPE
DDoS-for-hire
MOTIVATION
Financial gain (DDoS-as-a-service)
IMPACT
Systems Affected: IoT devices (D-Link, Netgear, Huawei, GPON)Operational Impact: Disruption of services due to DDoS attacks
DATA BREACH
Data Encryption: XOR-based encryption for C2 domains and payloads
MAY 2025
738Before Incident
Vulnerability
01 May 2025NETGEAR
Next.js, D-Link, Apache and Netgear: Cyberattack Trends & Variations: What Our Honeypots Reveal

Honeypot Data Reveals Persistent Cyber Threats: A Year in Exploit Trends (2025–2026)

733After Incident
CRITICAL-5
NETVERDLITHE1780583187
Honeypot Data Reveals Persistent Cyber Threats: A Year in Exploit Trends (2025–2026) Between May 2025 and May 2026, a global network of honeypots recorded over 9.2 million security events originating from 54,000 unique IP addresses across 163 countries, offering a snapshot of evolving cyber threats. The data, collected from strategically deployed decoy systems, highlights sustained attacker interest in vulnerable services, with SSH (75% of events) dominating activity reinforcing the risks of exposing the protocol directly to the internet. Web applications (10%) and SMTP services (10%) followed, while attacks on medical protocols remained negligible. ### Top Exploited Vulnerabilities Nine vulnerabilities stood out for their high exploitation rates, with React2Shell (CVE-2025-55182) a critical flaw in Next.js servers leading the pack. Disclosed in December 2025, it triggered a surge in attacks, with six IP addresses accounting for 90% of December’s activity. Other notable targets included: - ProxyLogon/ProxyShell/ProxyNotShell (Microsoft Exchange): Persistent exploitation since 2021, leveraging unpatched servers for SYSTEM-level access. - Shellshock (CVE-2014-6271): A decade-old Bash vulnerability still actively probed for initial access. - ThinkPHP (CVE-2018-25270): Sustained attacks on the Chinese PHP framework post-2026 disclosure. - Log4Shell (CVE-2021-44228): Declining but still targeted, reflecting its historical impact. - Legacy Router Flaws: D-Link Dir-645 (CVE-2015-2051) and Netgear DGN1000/DGN2000 (CVE-2024-12847) saw renewed activity, tied to campaigns like Rondodox. - CrushFTP (CVE-2025-54309): A single, concentrated attack on October 13, 2025, exploiting a race-condition flaw. ### Key Observations - Web applications faced relentless attacks, with CVEs like React2Shell and ProxyShell driving spikes. - Routers and IoT devices remained prime targets, often via decade-old vulnerabilities. - Exploit timelines varied: Some flaws (e.g., CrushFTP) saw brief, intense campaigns, while others (e.g., Shellshock) endured as persistent threats. - Attacker behavior aligned globally, with honeypot operators reporting similar patterns. The data underscores the longevity of high-impact vulnerabilities and the risks of unpatched systems, even years after disclosure. Honeypots continue to serve as critical tools for detecting emerging threats and attacker methodologies.
INCIDENT DETAILS -
TYPE
Exploit TrendsVulnerability Exploitation
IMPACT
Systems Affected: Decoy honeypot systems
NOVEMBER 2024
753Before Incident
Cyber Attack
01 Nov 2024NETGEAR
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach

735After Incident
LOW-18
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection. First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion. Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks. Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection. As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
DDoS-for-Hire Botnet
MOTIVATION
Financial gain (DDoS-for-hire service)Long-term survival with low visibility
IMPACT
IoT devices (routers, cameras, gateways)Disruption of CDNs, game servers, and enterprises via volumetric DDoS attacks
DATA BREACH
Data Encryption: XOR-based encryption

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for NETGEAR ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in July 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in June 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in May 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in April 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in March 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in February 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in January 2026 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in December 2025 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in November 2025 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in October 2025 ?
?
What was NETGEAR's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on NETGEAR's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with NETGEAR ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view NETGEAR's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
NETGEAR Cyber Scoring History | Rankiteo