ZDI-CAN-11076: NETGEAR Orbi UA_Parser Host Name Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UAParser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-11076?
The severity of ZDI-CAN-11076 is high due to its ability to allow remote code execution without authentication.
How do I fix ZDI-CAN-11076?
To fix ZDI-CAN-11076, you should update your NETGEAR Orbi router to the latest firmware version provided by NETGEAR.
Who is affected by ZDI-CAN-11076?
ZDI-CAN-11076 affects installations of NETGEAR Orbi routers that utilize the vulnerable UA_Parser utility.
Can ZDI-CAN-11076 be exploited remotely?
Yes, ZDI-CAN-11076 can be exploited remotely by network-adjacent attackers.
Is authentication required for exploiting ZDI-CAN-11076?
No, ZDI-CAN-11076 can be exploited without any authentication.