ZDI-CAN-22430: ZDI-24-832: (Pwn2Own) Synology RT6600ax Improper Access Control Firewall Bypass Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows remote attackers to bypass firewall rules and access the LAN interface on affected installations of Synology RT6600ax routers. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.6. The following CVEs are assigned: CVE-2024-39347.
Affected Software
1 affected component
Synology RT6600ax
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22430?
ZDI-CAN-22430 has a CVSS rating of 6.6, indicating a medium severity level.
2
How do I fix ZDI-CAN-22430?
To mitigate ZDI-CAN-22430, ensure that you update your Synology RT6600ax router to the latest firmware version provided by Synology.
3
What type of vulnerabilities does ZDI-CAN-22430 represent?
ZDI-CAN-22430 represents a remote code execution vulnerability that allows attackers to bypass firewall rules.
4
Who is affected by ZDI-CAN-22430?
ZDI-CAN-22430 affects installations of Synology RT6600ax routers.
5
Is authentication required to exploit ZDI-CAN-22430?
Yes, authentication is required to exploit ZDI-CAN-22430.