Gateway takeover

Anonymous
Not applicable

I do believe my 5G admin page has been compromised & it’s like someone else is the account owner & able to make more settings. I can’t get to lots of settings like firewall, client list, network map, ….. I’ve discovered lots of suspicious port forwarding rules, & can’t see IPv6 address distribution but see all kinds of suspicious IPv6 addys. I was severely hacked two months ago & someone operating in the background could explain a lot.

0 Likes
25 Replies
vzw_customer_support
Customer Service Rep

Hey there, Incognitoky, we know how important the security of your account is! Are you seeing something has changed that you did not update? Have you had the opportunity to update your password recently? What model gateway are you using?

-Lauren

Anonymous
Not applicable

I’m pretty sure it’s been compromised. Can’t even see firewall settings, no network map or client list, & I could go on & on. Can’t make changes to settings lots of places & screen looks funny at lots of admin pages. I continue to see a NETGEAR_EXT unsecured on my Wi-Fi list in Apple settings & when looking at it, I see notes in referring to my Apple settings. Could that be just the router separated from me by hacker? After all, I see no way to get to my router settings. There’s just so many things that look real funny. I believe the hacker is logged into many of my apps & just waits till I log in & gets in my network. I’ve seen several apps with me logged in all over the country & a couple were foreign countries. Weird stuff.

0 Likes
Anonymous
Not applicable

I’ve changed password several times over the past couple weeks. 
ASK-NCQ1338FA

I still have never been able to access firewall, client list, router, or many other settings. I still have cyber attacks when I open an app I haven’t used in a few months & I think they’re using them to get in my network. Also, I don’t believe I ever set up the admin page when I first got the gateway. That would explain them getting in my network & modifying the router settings. I think they’re using me for the internet access. Please help me.

0 Likes
Anonymous
Not applicable

My network is still unacceptable!

0 Likes
vzw_customer_support
Customer Service Rep

We're sorry to read that you are having issues with your network. We're here to help.  What kind of speeds are you getting? ~Peter

0 Likes
unwiredsoul
Contributor - Level 2

Factory reset the router ASAP and then set a properly secure and unique password. Perform the steps with a device (mobile phone w/Wi-Fi?) that you are confident is not already compromised.

Otherwise, there are a lot of variables going on. If you believe you still have compromised devices then you've got a larger challenge to address than your Internet router being hijacked. It will just keep happening until your environment is no longer compromised. That's going to be unique to your situation but may entail clean OS reinstallation on computers, etc.

I'm sorry you're having this challenge and that you were hacked. Once you've been hacked it can be a real pain to recover from.

Good luck!

Anonymous
Not applicable

I do believe my iPhone & iPad are clean. When anything weird & suspicious happens, it’s always centered around android apps. I no longer use any non-apple devices except my Roku TV & Vizio sound bar are exposed but they can’t get anywhere. What’s weird is I found a NETGEAR_EXT available on my Wi-Fi list & it says it’s my network. I also found entries in the log showing the IP address & MAC from that. It’s weird like they’ve gotten my router separated from the gateway. 
it’s definitely compromised. HELP

0 Likes
Anonymous
Not applicable

it’s like they declared themselves account owner of only the 5G Gateway only. Even the Verizon App acts funny sometimes trying to access gateway. It won’t let me do some things & shows errors & even says contact customer service. Something ain’t right.

0 Likes
Anonymous
Not applicable

I’ve done several factory resets using my mobile on cell data & still no success.

0 Likes
Anonymous
Not applicable
  1. [FW] IPTABLES [Pkt_Illegal] IN=br-lan OUT=rmnet_data3 MAC=fc:12:63:27:5a:55:4e:ab:36:bb:ea:e7:08:00 src=192.168.0.160 DST=17.137.162.3 LEN=83 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=60193 DPT=443 WINDOW=8224 RES=0x00 ACK PSH FIN URGP=0
  2. This was on the Firewall Log. Look at that MAC ID. fc:12:63:27:5a:55 is the MAC ID of that unsecure NETGEAR_EXT on my Wi-Fi list.
0 Likes
vzw_customer_support
Customer Service Rep

I am sorry you are still having issues with you Gateway. We can take a look at the connected devices to see if this Netgear is connect and steps to remove it. Do yo have any devices connected by ethernet?

-Deb

0 Likes
Anonymous
Not applicable

The hacker managed to get the router separated from the gateway & it’s sitting out there as NETGEAR_EXT.  I see the IP address in the firewall logs. I have nothing connected to the Ethernet & have disabled them. Hey Deb, I didn’t setup the new gateway today. I’d like to clean up a couple things first. Now I’m locked out of my Verizon Home app I just setup yesterday. I’m sure the hacker has something to do with that. I can tell when he gets into my gateway and 5G account. You start seeing double circles when navigating thru the home account & I can never get the gateway settings to come up in the Verizon app. 

0 Likes
vzw_customer_support
Customer Service Rep

Hey there, Incognitoky, sorry to hear you're running into some trouble accessing your app. To clarify, are you looking to sign in to My Verizon? If so, what happens when trying to sign in? Does it help to go through the steps to reset your password?

-Lauren

0 Likes
unwiredsoul
Contributor - Level 2


If I were Verizon, I'd send you new hardware and then advise you take the following steps when setting up the replacement (from your iPad as it's "known clean"). Since I'm just a fellow customer, I would suggest a clean reset of the router (using a paper clip or similar to physically reset it using the button on the bottom of the device). Then, I'd look at what I've shared below...

Also, when I reference the "web admin" page, it's using a web browser to go to the IP address of the 5G gateway, and then logging in with the default password on the bottom of the gateway. I share this for clarity so that we're both sure we're talking about the same thing. I believe we are but best to over-communicate when troubleshooting complex situations on a community forum. 😀

  • Secure the device with the non-factory password  for the web admin page
  • Use *only* the web admin page to configure new passwords for the Wi-Fi networks
  • Use *only* the web admin page to configure Device access to Block/Allow only your devices
    • Parental Controls or from the Device tab in the Advanced settings section

I need to underscore my point about using *only* the web admin page. The mobile app., just isn't as fast or capable as the web admin page for any of this. Also, make sure you do not check the "Stay signed in..." button. Especially with everything going on it's important that you stay signed out of the router as an admin when you aren't making changes.

I've attached a screenshot from my 5G gateway that highlights various topics I've posted about here.:

VZW-5GHome-GW.jpg

 

0 Likes
Anonymous
Not applicable

Hey unwiredsoul, thanks for the reply. Your screenshot didn’t come through. It’s probably a Verizon thing. I’ve been leaving my admin up all the time. I now sign out when leaving. I gotta ask you a few things.

Do you see firewall, client list, network map, cellular, virtual servers, QOS settings? I don’t & do you have router settings? Again, I don’t & I see a NETGEAR_EXT on my WiFi list in all device settings. That doesn’t seem right. And, I can’t get to gateway settings on Verizon app..

Oh, I got the new gateway yesterday but I wanna clean up things before installing.

Thanks a bunch for input.

0 Likes
unwiredsoul
Contributor - Level 2

That is odd about the screenshot as it's embedded as part of my post. However, if you're reading this on the mobile app., I can only guess if it shows images. I really don't use the mobile app., very often as it has limited functionality compared to the Web Admin interface.

Thankfully, the User Manual has screenshots of the settings I'm referencing:  https://scache.vzw.com/dam/support/pdf/user_guide/Verizon-Internet-Gateway-User-Guide-2023.pdf

If you are not seeing what the User Manual shows for the web interface on your router, then the most likely cause is that it is running very outdated firmware from (at least) sometime last year (2023). If it hasn't update firmware in that long, I'd stop trying to make the current router work and implement the new router ASAP (I would do that anyhow).

Regarding what I see in the web interface:

  • In the Advanced tab there is a Security & Firewall section that contains features like setting General Firewall, Port Forwarding, etc. (See Page 64 in the User Manual I shared a link to above).
  • I am not aware of any QoS settings in Verizon 5G Home Internet devices. The closest thing is SIP ALG and in most cases it's best to leave that off. But, the type of QoS settings you'd normally expect to find just are not there. The device and network handle packet prioritization.
  • The top tab is Devices and that's where you'll find the client list and toggle buttons to disallow traffic.
  • Virtual Servers isn't called that in any settings on the router. You will need to use features like DMZ HostPort Forwarding, and potentially IPv6 Pinholes to setup those features.

A couple of other general thoughts for the new router (or existing) once you're able to get to the settings of either:

  • Disable UPnP (Universal Plug & Play)
  • Disable all non-essential Wi-Fi networks (e.g., Guest and IoT networks)
0 Likes
Anonymous
Not applicable

I’ve never seen General Firewall settings anywhere on the admin page. Under Devices, I only see mine as I’ve identified all the MAC ID’s. I don’t see anything that looks like you’re indicating. Also, all my IPv6 connections are disabled. I see none. OH, when I connect to that NETGEAR_EXT Wi-Fi device, it idicates there’s some hidden apps. I don’t know why Verizon reps don’t believe me. Verizon is sending another replacement 5G Gateway. Should be here Wednesday. Also, I’m also locked out if Verizon Home Internet app. Verizon rep said today to only use the Verizon app to manage my account & not the admin page. Geez, these reps are pulling me different directions. 

0 Likes
vzw_customer_support
Customer Service Rep

Hello, Incognitoky. Please be sure to reach out to us once your new device arrives so that we can assist if any issues persist. 

 

-Natasha

0 Likes
Anonymous
Not applicable

Natasha, all of a sudden, I was able to sign into Verizon Home app & saw my networks & devices, & a network map for the first time ever. It’s as if IT suddenly fixed it. Super weird but very welcome. I’ll reach out when the replacement Gateway gets here. I still see that odd NETGEAR_EXT Wi-Fi device out there & warnings in the firewall log but see some IPv6 connections for the first time in awhile. ODD?

0 Likes
vzw_customer_support
Customer Service Rep

Incognitoky, thank you for keeping us posted. To best assist, we'll be sending a Private Message. 

~Izzy

0 Likes