NETGEAR A.I CyberSecurity Scoring
NETGEAR
Company Information
Website:http://www.netgear.com
Employees number:1,420
Number of followers:70,522
NAICS:5112
Industry Type:Software Development
Homepage:netgear.com
NETGEAR Risk Score (AI oriented)
Between 700 and 749
NETGEARSoftware Development
Updated:
17/08/2026
17/08/2026
718/1000
Moderate
Ba
NETGEAR Global Score (TPRM)
xxxx
NETGEARSoftware Development
Score locked

NETGEARModerate
Current Score
718Ba (MODERATE)
01000
5 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
718
JULY 2026
721
Vulnerability
01 Jul 2026 • NETGEAR
NETGEAR, Tenda, Alcatel, Mitsubishi Electric and D-Link: Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft
New Linux Botnet Evooo1Bot Emerges, Targeting Edge Devices for DDoS and Cybercrime
716
CRITICAL-5
NETALCTENMITDLI1786947932
New Linux Botnet Evooo1Bot Emerges, Targeting Edge Devices for DDoS and Cybercrime
FortiGuard Labs has identified a previously unknown Linux botnet, Evooo1Bot, named after the "evooo1" string embedded in its malware samples. Active since July 2026, the botnet compromises internet-facing routers, firewalls, cameras, and other edge devices, repurposing them for DDoS attacks, SOCKS5 proxy relays, credential theft, and network intrusion.
### Capabilities and Tactics
Evooo1Bot builds on the Mirai source code but expands its functionality with:
- Encrypted C2 communication (AES, ChaCha20, XOR)
- SSH brute-forcing, traffic sniffing, and remote shell access
- Exploit modules targeting vulnerabilities in Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link devices
- Anti-analysis checks for debugging tools (GDB, Wireshark), sandboxes, and virtual environments
- Persistence mechanisms, including fake systemd services, cron jobs, and shell-profile modifications
The malware downloads payloads from 91.92.40[.]118/wget.sh, which detects the target’s CPU architecture before executing the appropriate binary. It also clears Bash history to erase traces of infection.
### Operational Impact
Evooo1Bot communicates over TCP port 443, blending into legitimate HTTPS traffic. Its C2 infrastructure supports remote commands for system reconnaissance, file transfers, and interactive shell access, while its persistence module ensures survival across reboots.
Operators appear to track infection success by vulnerability and device type, suggesting a structured campaign. The botnet’s multi-layered encryption and evasion techniques make detection and analysis challenging.
### Indicators of Compromise (IOCs)
- C2/Payload Server: 91.92.40[.]118
- Loader URL: http://91.92.40[.]118/wget.sh
The discovery highlights the growing threat of botnets targeting unpatched edge devices, underscoring the need for robust network security measures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
721
MAY 2026
721
APRIL 2026
719
MARCH 2026
719
FEBRUARY 2026
722
Vulnerability
26 Feb 2026 • NETGEAR
Tenda, TP-Link and Netgear: Researchers discover massive Wi-Fi vulnerability affecting multiple access points — AirSnitch lets attackers on the same network intercept data and launch machine-in-the-middle attacks
AirSnitch: Wi-Fi Vulnerability Exploiting Network Stack Weaknesses
717
CRITICAL-5
TENTP-NET1772144683
Researchers Uncover Wi-Fi Vulnerability "AirSnitch" Exploiting Network Stack Weaknesses
A team of researchers from the University of California, Riverside, has identified a critical flaw in Wi-Fi security dubbed AirSnitch, which allows attackers to intercept network traffic even on networks with client isolation enabled. The vulnerability exploits gaps in how Wi-Fi links MAC addresses, encryption keys, and IP addresses across network layers (1, 2, and 3), enabling attackers to impersonate devices and reroute traffic.
Lead researcher Xin’an Zhou warned that AirSnitch "breaks worldwide Wi-Fi encryption" and could facilitate advanced attacks, including cookie theft, DNS poisoning, and cache manipulation, by effectively wiretapping the network. Unlike traditional exploits, AirSnitch does not crack encryption but instead undermines the assumption that encrypted clients are fully isolated from one another.
The attack leverages four primary methods to bypass client isolation:
1. Shared Key Abuse – Exploiting the Group Temporal Key (GTK) used in most networks to broadcast malicious packets disguised as legitimate traffic.
2. Gateway Bouncing – Sending data to an access point addressed to a gateway MAC, tricking the gateway into forwarding it to the victim.
3. MAC Spoofing (Downlink) – Mimicking a victim’s MAC address to intercept their incoming traffic.
4. MAC Spoofing (Uplink) – Impersonating backend devices (e.g., gateways) to capture outgoing traffic from a target.
The vulnerability was confirmed across five consumer routers (Netgear Nighthawk x6 R8000, Tenda RX2 Pro, D-LINK DIR-3040, TP-Link Archer AXE75, Asus RT-AX57), two open-source firmwares (DD-WRT v3.0-r44715, OpenWrt 24.10), and two university enterprise networks, indicating the flaw is inherent to Wi-Fi architecture rather than specific hardware.
While the attack is complex, researchers emphasize that the findings highlight systemic weaknesses in Wi-Fi security, urging manufacturers and standards bodies to address these flaws in future protocols. The discovery underscores the need for stronger client isolation mechanisms to prevent such exploits.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
721
DECEMBER 2025
720
NOVEMBER 2025
719
OCTOBER 2025
718
SEPTEMBER 2025
717
JULY 2025
735
Cyber Attack
30 Jul 2025 • NETGEAR
Netgear and D-Link: Masjesu Botnet Targets Routers and Gateways For Paid DDoS Attacks
Masjesu Botnet: A Stealthy, Evolving IoT Threat for DDoS-as-a-Service
715
HIGH-20
DLINET1775644215
Masjesu Botnet: A Stealthy, Evolving IoT Threat for DDoS-as-a-Service
The Masjesu botnet, first detected in early 2023 and still active through 2026, has established itself as a highly sophisticated DDoS-for-hire service targeting Internet of Things (IoT) devices. Unlike traditional botnets that rely on large-scale, noisy infections, Masjesu prioritizes stealth and long-term persistence, avoiding high-profile networks like U.S. Department of Defense systems to evade detection and legal action.
### Stealth Tactics & Operational Methods
Masjesu employs advanced evasion techniques to bypass security measures, including:
- XOR-based encryption to conceal command-and-control (C2) domains and payloads, decrypting them only at runtime.
- Hardened persistence by binding to a hardcoded TCP port and ignoring termination signals.
- Process masquerading, renaming its executable to mimic legitimate system files (e.g., a Linux dynamic linker) and using cron jobs to re-execute every 15 minutes.
### Exploitation & Propagation
The botnet spreads by scanning random IP addresses for vulnerable open ports, targeting devices from manufacturers like D-Link, Netgear, Huawei, and GPON. Upon exploitation, it deploys a malicious shell script to recruit devices into its network. Once integrated, bots receive instructions to launch DDoS attacks under a unique "masjesu" user-agent.
### Defensive Measures & Impact
Due to its obfuscation-heavy approach, traditional antivirus detection is often ineffective. Organizations are advised to:
- Monitor outbound traffic for unusual HTTP requests or connections to known malicious domains.
- Implement process and file integrity monitoring to detect spoofed system files or unauthorized cron jobs.
- Enforce basic IoT security hygiene, including changing default credentials and applying firmware updates to patch known vulnerabilities.
Masjesu’s commercial DDoS-for-hire model and low-profile operations make it a persistent threat, underscoring the need for behavior-based defenses in IoT security.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
738
Vulnerability
01 May 2025 • NETGEAR
Next.js, D-Link, Apache and Netgear: Cyberattack Trends & Variations: What Our Honeypots Reveal
Honeypot Data Reveals Persistent Cyber Threats: A Year in Exploit Trends (2025–2026)
733
CRITICAL-5
NETVERDLITHE1780583187
Honeypot Data Reveals Persistent Cyber Threats: A Year in Exploit Trends (2025–2026)
Between May 2025 and May 2026, a global network of honeypots recorded over 9.2 million security events originating from 54,000 unique IP addresses across 163 countries, offering a snapshot of evolving cyber threats. The data, collected from strategically deployed decoy systems, highlights sustained attacker interest in vulnerable services, with SSH (75% of events) dominating activity reinforcing the risks of exposing the protocol directly to the internet. Web applications (10%) and SMTP services (10%) followed, while attacks on medical protocols remained negligible.
### Top Exploited Vulnerabilities
Nine vulnerabilities stood out for their high exploitation rates, with React2Shell (CVE-2025-55182) a critical flaw in Next.js servers leading the pack. Disclosed in December 2025, it triggered a surge in attacks, with six IP addresses accounting for 90% of December’s activity. Other notable targets included:
- ProxyLogon/ProxyShell/ProxyNotShell (Microsoft Exchange): Persistent exploitation since 2021, leveraging unpatched servers for SYSTEM-level access.
- Shellshock (CVE-2014-6271): A decade-old Bash vulnerability still actively probed for initial access.
- ThinkPHP (CVE-2018-25270): Sustained attacks on the Chinese PHP framework post-2026 disclosure.
- Log4Shell (CVE-2021-44228): Declining but still targeted, reflecting its historical impact.
- Legacy Router Flaws: D-Link Dir-645 (CVE-2015-2051) and Netgear DGN1000/DGN2000 (CVE-2024-12847) saw renewed activity, tied to campaigns like Rondodox.
- CrushFTP (CVE-2025-54309): A single, concentrated attack on October 13, 2025, exploiting a race-condition flaw.
### Key Observations
- Web applications faced relentless attacks, with CVEs like React2Shell and ProxyShell driving spikes.
- Routers and IoT devices remained prime targets, often via decade-old vulnerabilities.
- Exploit timelines varied: Some flaws (e.g., CrushFTP) saw brief, intense campaigns, while others (e.g., Shellshock) endured as persistent threats.
- Attacker behavior aligned globally, with honeypot operators reporting similar patterns.
The data underscores the longevity of high-impact vulnerabilities and the risks of unpatched systems, even years after disclosure. Honeypots continue to serve as critical tools for detecting emerging threats and attacker methodologies.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
NOVEMBER 2024
753
Cyber Attack
01 Nov 2024 • NETGEAR
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
735
LOW-18
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection.
First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion.
Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks.
Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection.
As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NETGEAR ??
What was NETGEAR's A.I Rankiteo Cyber Score in July 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in June 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in May 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in April 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in March 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in February 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in January 2026 ??
What was NETGEAR's A.I Rankiteo Cyber Score in December 2025 ??
What was NETGEAR's A.I Rankiteo Cyber Score in November 2025 ??
What was NETGEAR's A.I Rankiteo Cyber Score in October 2025 ??
What was NETGEAR's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on NETGEAR's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NETGEAR ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NETGEAR's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?