ZDI-CAN-19754: ZDI-23-502: (Pwn2Own) NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19754?
The severity of ZDI-CAN-19754 is critical due to the potential for remote code execution.
How do I fix ZDI-CAN-19754?
To fix ZDI-CAN-19754, ensure that you update your NETGEAR RAX30 router to the latest firmware version provided by the manufacturer.
Who is affected by the ZDI-CAN-19754 vulnerability?
The ZDI-CAN-19754 vulnerability affects installations of NETGEAR RAX30 routers that are accessible to network-adjacent attackers.
What type of attackers can exploit ZDI-CAN-19754?
Network-adjacent attackers can exploit the ZDI-CAN-19754 vulnerability without requiring authentication.
What are the consequences of exploiting ZDI-CAN-19754?
Exploiting ZDI-CAN-19754 can allow attackers to execute arbitrary code on the affected NETGEAR RAX30 routers.