ZDI-CAN-12216: (Pwn2Own) NETGEAR R7800 udchpd DHCP_REQUEST Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendorspecific DHCP opcode. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-12216?
ZDI-CAN-12216 has a critical severity rating due to its potential for remote code execution.
How do I fix ZDI-CAN-12216?
To resolve ZDI-CAN-12216, update the NETGEAR R7800 firmware to the latest version provided by the vendor.
Can ZDI-CAN-12216 be exploited remotely?
Yes, ZDI-CAN-12216 can be exploited by network-adjacent attackers without requiring authentication.
What type of devices are impacted by ZDI-CAN-12216?
ZDI-CAN-12216 affects NETGEAR R7800 routers.
Is user interaction required to exploit ZDI-CAN-12216?
No, no user interaction is required to exploit ZDI-CAN-12216.