ZDI-24-832: (Pwn2Own) Synology RT6600ax Improper Access Control Firewall Bypass Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows remote attackers to bypass firewall rules and access the LAN interface on affected installations of Synology RT6600ax routers. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.6. The following CVEs are assigned: CVE-2024-39347.
Affected Software
1 affected component
Synology RT6600ax
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-832?
The severity of ZDI-24-832 is rated at 6.6 on the CVSS scale.
2
How do I fix ZDI-24-832?
To fix ZDI-24-832, ensure that your Synology RT6600ax router firmware is updated to the latest version which addresses this vulnerability.
3
What is the impact of ZDI-24-832?
The impact of ZDI-24-832 allows remote attackers to bypass firewall rules and access the LAN interface.
4
Is authentication required to exploit ZDI-24-832?
Yes, authentication is required to exploit ZDI-24-832.
5
What devices are affected by ZDI-24-832?
ZDI-24-832 affects Synology RT6600ax routers.