ZDI-CAN-19743: ZDI-23-1341: Synology RT6600ax uistrings.cgi Path Traversal Information Disclosure Vulnerability
Published Sep 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Synology RT6600ax routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2023-41740.
Affected Software
1 affected component
Synology RT6600ax
Event History
Sep 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19743?
The severity of ZDI-CAN-19743 is rated at 4.3 on the CVSS scale.
2
What types of attacks can exploit ZDI-CAN-19743?
ZDI-CAN-19743 can be exploited by network-adjacent attackers to disclose sensitive information.
3
Is authentication required to exploit ZDI-CAN-19743?
No, authentication is not required to exploit ZDI-CAN-19743.
4
Which devices are affected by ZDI-CAN-19743?
ZDI-CAN-19743 affects Synology RT6600ax routers.
5
How can I mitigate the risks associated with ZDI-CAN-19743?
To mitigate the risks associated with ZDI-CAN-19743, ensure that your Synology RT6600ax router firmware is updated to the latest version.