ZDI-23-661: (Pwn2Own) Synology RT6600ax Command Injection Remote Code Execution Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology RT6600ax routers. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Synology RT6600ax
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-661?
The severity of ZDI-23-661 is critical due to the ability for network-adjacent attackers to execute arbitrary code.
2
How do I fix ZDI-23-661?
To fix ZDI-23-661, update the firmware of your Synology RT6600ax router to the latest version provided by Synology.
3
Who is affected by ZDI-23-661?
Users of the Synology RT6600ax router are affected by the ZDI-23-661 vulnerability.
4
Can ZDI-23-661 be exploited remotely?
No, ZDI-23-661 requires network adjacency to exploit, meaning the attacker must be on the same local network.
5
Is authentication required to exploit ZDI-23-661?
No, ZDI-23-661 can be exploited without any authentication.