Lucene search

K
zdiClaroty Research - Vera Mens, Noam Moshe, Uri Katz, Sharon BrizinovZDI-24-072
HistoryJan 15, 2024 - 12:00 a.m.

Synology RT6600ax Qualcomm LDB Service Improper Input Validation Remote Code Execution Vulnerability

2024-01-1500:00:00
Claroty Research - Vera Mens, Noam Moshe, Uri Katz, Sharon Brizinov
www.zerodayinitiative.com
29
vulnerability
network-adjacent
synology rt6600ax
qualcomm
ldb service
improper input validation
remote code execution

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

47.6%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology RT6600ax routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Qualcomm LDB service. The issue results from the lack of proper validation of user-supplied data prior to further processing. An attacker can leverage this vulnerability to execute code in the context of root.

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

47.6%

Related for ZDI-24-072