Skip to content

Instantly share code, notes, and snippets.

View driverdan's full-sized avatar

Dan DeFelippi driverdan

View GitHub Profile
@driverdan
driverdan / netgear-private-key-disclosure.md
Created January 20, 2020 16:22 — forked from nstarke/netgear-private-key-disclosure.md
Netgear TLS Private Key Disclosure through Device Firmware Images

Netgear Signed TLS Cert Private Key Disclosure

Overview

There are at least two valid, signed TLS certificates that are bundled with publicly available Netgear device firmware.

These certificates are trusted by browsers on all platforms, but will surely be added to revocation lists shortly.

The firmware images that contained these certificates along with their private keys were publicly available for download through Netgear's support website, without authentication; thus anyone in the world could have retrieved these keys.