ZDI-23-1010: Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability
Published Jul 28, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Adtran SR400ac
Event History
Jul 28, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:12 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1010?
ZDI-23-1010 is classified as a high-severity vulnerability that allows remote code execution.
2
How do I fix ZDI-23-1010?
To fix ZDI-23-1010, apply the security updates provided by Adtran for the SR400ac routers.
3
Who is affected by ZDI-23-1010?
ZDI-23-1010 affects installations of Adtran SR400ac routers.
4
Can ZDI-23-1010 be exploited without authentication?
No, exploitation of ZDI-23-1010 requires authentication, although the mechanism can be bypassed.
5
What can attackers do with ZDI-23-1010?
Attackers can execute arbitrary code on affected Adtran SR400ac routers due to ZDI-23-1010.