ZDI-23-1340: Synology RT6600ax SYNO.Core Uncontrolled Resource Consumption Denial-of-Service Vulnerability
Published Sep 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Synology RT6600ax routers. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.7. The following CVEs are assigned: CVE-2023-41739.
Affected Software
1 affected component
Synology RT6600ax
Event History
Sep 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1340?
The severity of ZDI-23-1340 is rated at 5.7 on the CVSS scale.
2
Who can exploit the ZDI-23-1340 vulnerability?
Only authenticated network-adjacent attackers can exploit the ZDI-23-1340 vulnerability.
3
What device is affected by the ZDI-23-1340 vulnerability?
The ZDI-23-1340 vulnerability affects Synology RT6600ax routers.
4
What is the impact of exploiting ZDI-23-1340?
Exploiting ZDI-23-1340 can lead to a denial-of-service condition on the affected routers.
5
How do I fix ZDI-23-1340?
To fix ZDI-23-1340, ensure your Synology RT6600ax router firmware is updated to the latest version.