ZDI-23-1766: Extreme Networks AP410C ah_webui Missing Authentication for Critical Function Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to reach critical functions on affected installations of Extreme Networks AP410C routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ahwebui service, which listens on TCP port 3009 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code within the context of root.
Other sources
This vulnerability allows network-adjacent attackers to reach critical functions on affected installations of Extreme Networks AP410C routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-46271.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1766?
The severity of ZDI-23-1766 is critical due to the lack of authentication required to exploit this vulnerability.
How do I fix ZDI-23-1766?
To fix ZDI-23-1766, update the firmware of your Extreme Networks AP410C to the latest version provided by the vendor.
Who is affected by ZDI-23-1766?
ZDI-23-1766 affects installations of Extreme Networks AP410C routers.
What type of attacks does ZDI-23-1766 allow?
ZDI-23-1766 allows network-adjacent attackers to access critical functions on the affected routers.
What component is vulnerable in ZDI-23-1766?
The vulnerability exists within the ah_webui service that listens on TCP port on the affected devices.