ZDI-CAN-19741: ZDI-23-1339: Synology RT6600ax WEB API Endpoint Command Injection Remote Code Execution Vulnerability
Published Sep 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology RT6600ax routers. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2023-41738.
Affected Software
1 affected component
Synology RT6600ax
Event History
Sep 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19741?
The severity of ZDI-CAN-19741 is rated at 8.0 on the CVSS scale.
2
How do I fix ZDI-CAN-19741?
To fix ZDI-CAN-19741, update your Synology RT6600ax router firmware to the latest version provided by Synology.
3
Who is affected by ZDI-CAN-19741?
The ZDI-CAN-19741 vulnerability affects installations of Synology RT6600ax routers.
4
Can ZDI-CAN-19741 be exploited remotely?
No, ZDI-CAN-19741 requires authentication, so it cannot be exploited remotely by unauthenticated users.
5
What type of attack does ZDI-CAN-19741 facilitate?
ZDI-CAN-19741 allows network-adjacent attackers to execute arbitrary code on affected installations.