ZDI-23-893: NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-893?
The severity of ZDI-23-893 is considered high due to the potential for compromise of downloaded information without authentication.
How do I fix ZDI-23-893?
To fix ZDI-23-893, users should apply the latest firmware updates released by NETGEAR for the affected routers.
What systems are affected by ZDI-23-893?
ZDI-23-893 affects multiple NETGEAR routers that are vulnerable to integrity compromise of downloaded information.
Can ZDI-23-893 be exploited remotely?
ZDI-23-893 can be exploited by network-adjacent attackers, meaning they need to be on the same network as the target.
Is authentication required to exploit ZDI-23-893?
No, authentication is not required to exploit ZDI-23-893, making it easier for attackers to execute the attack.