The update fixes XSS and CSRF security vulnerabilities

Mar 22, 2017 15:06 GMT  ·  By

NETGEAR has made available a new firmware package compatible with its GSS116E switch model, namely version 1.0.0.5, which adds a Switch Management Mode to the Web GUI that allows users to choose how to manage their switches.

In addition to that, the present update fixes Cross-site Scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities, and implements a more secure encryption algorithm to work with the new NETGEAR GSS116E Switch Configuration Utility 2.4.3 and higher.

In terms of installation, get and unzip the downloadable archive from the links below, install the 2.4.3 utility, save the switch’s current configuration, establish a wired connection between it and your computer, and log into its dashboard (username and password should be required).

Now, go to System > Maintenance > Firmware Upgrade, click the “Browse” button, navigate and select the newly unzipped .img file, click “Upload,” and wait as your switch does its job.

However, while upgrading, you mustn’t reboot/power off either the switch or the computer, remove the Ethernet cable, or interrupt the process in any way. Doing so might cause various malfunctions that you would rather avoid.

That said, download NETGEAR GSS116E Switch Firmware 1.0.0.5, and carefully apply it to your unit. Also, check our website as often as possible to be aware when newer versions are available for your device.