Lucene search

K
zdiRocco Calvi and Steven Seeley of Incite TeamZDI-23-496
HistoryMay 01, 2023 - 12:00 a.m.

NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability

2023-05-0100:00:00
Rocco Calvi and Steven Seeley of Incite Team
www.zerodayinitiative.com
29
netgear
rax30
lighttpd
misconfiguration
remote code execution
vulnerability
authentication
http server
untrusted sources
root

EPSS

0.001

Percentile

16.2%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the lighttpd HTTP server. The issue results from allowing execution of files from untrusted sources. An attacker can leverage this vulnerability to execute code in the context of root.

EPSS

0.001

Percentile

16.2%

Related for ZDI-23-496