ZDI-CAN-19723: ZDI-23-917: NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability
Published Jul 13, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Netgear ProSAFE Network Management System
Event History
Jul 13, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 23, 2025
Advisory Published
via ZDI·04:03 PM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19723?
The severity of ZDI-CAN-19723 is high due to the potential for remote code execution by attackers.
2
How do I fix ZDI-CAN-19723?
To fix ZDI-CAN-19723, update the NETGEAR ProSAFE Network Management System to the latest version provided by NETGEAR.
3
What systems are affected by ZDI-CAN-19723?
ZDI-CAN-19723 affects installations of the NETGEAR ProSAFE Network Management System.
4
Can ZDI-CAN-19723 be exploited without authentication?
No, exploitation of ZDI-CAN-19723 requires authentication, but the existing authentication mechanism can be bypassed.
5
What type of vulnerability is ZDI-CAN-19723?
ZDI-CAN-19723 is a remote code execution vulnerability.