ZDI-23-917: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability
Published Jul 13, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Netgear ProSAFE Network Management System
Event History
Jul 13, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 23, 2025
Advisory Published
via ZDI·04:03 PM
Frequently Asked Questions
1
What is the severity of ZDI-23-917?
ZDI-23-917 is considered critical due to its potential to allow remote code execution.
2
How do I fix ZDI-23-917?
To fix ZDI-23-917, you should apply the latest security patches provided by NETGEAR for the ProSAFE Network Management System.
3
What systems are affected by ZDI-23-917?
ZDI-23-917 affects installations of the NETGEAR ProSAFE Network Management System.
4
Is authentication required to exploit ZDI-23-917?
Yes, authentication is required, but the existing authentication mechanism can be bypassed.
5
Can ZDI-23-917 be exploited remotely?
Yes, remote attackers can exploit ZDI-23-917 to execute arbitrary code on affected systems.