ZDI-23-1163: NETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1163?
ZDI-23-1163 is considered critical due to its potential to allow arbitrary code execution.
How do I fix ZDI-23-1163?
To fix ZDI-23-1163, ensure that your NETGEAR RAX30 router is updated to the latest firmware version provided by NETGEAR.
Who is affected by ZDI-23-1163?
ZDI-23-1163 affects installations of NETGEAR RAX30 routers that permit network-adjacent access.
What type of attack can be executed through ZDI-23-1163?
ZDI-23-1163 allows network-adjacent attackers to execute arbitrary code by bypassing existing authentication mechanisms.
Is authentication required to exploit ZDI-23-1163?
Yes, although authentication is required to exploit ZDI-23-1163, it can be bypassed due to the vulnerability's nature.