ZDI-23-1718: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getNodesByTopologyMapSearch function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-44450.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1718?
ZDI-23-1718 has a critical severity rating due to its potential for remote code execution.
How do I fix ZDI-23-1718?
To fix ZDI-23-1718, ensure you update to the latest version of the NETGEAR ProSAFE Network Management System as provided in the security advisory.
What is the impact of ZDI-23-1718?
The impact of ZDI-23-1718 allows remote attackers to execute arbitrary code on the affected system once authenticated.
Does ZDI-23-1718 require authentication for exploitation?
Yes, ZDI-23-1718 requires authentication to exploit the vulnerability.
What software is affected by ZDI-23-1718?
The vulnerability ZDI-23-1718 affects the NETGEAR ProSAFE Network Management System.