ZDI-CAN-13511: NETGEAR R6260 setupwizard.cgi Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. A crafted SOAP request can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-13511?
The severity of ZDI-CAN-13511 is critical due to its potential for remote code execution without authentication.
How do I fix ZDI-CAN-13511?
To fix ZDI-CAN-13511, users should update their NETGEAR R6260 routers to the latest firmware version provided by NETGEAR.
Who is affected by ZDI-CAN-13511?
ZDI-CAN-13511 affects NETGEAR R6260 routers running vulnerable firmware versions.
Can ZDI-CAN-13511 be exploited remotely?
Yes, ZDI-CAN-13511 can be exploited remotely by network-adjacent attackers without needing authentication.
What are the implications of ZDI-CAN-13511?
The implications of ZDI-CAN-13511 include the ability for attackers to execute arbitrary code, potentially compromising the router and connected devices.