NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability
CVE-2023-35722
What is CVE-2023-35722?
A vulnerability exists in the NETGEAR RAX30 router that allows network-adjacent attackers to execute arbitrary code through a flaw in the handling of UPnP port mapping requests. This is due to insufficient validation of a user-supplied string before it is utilized to execute a system command. The attacker does not need to be authenticated to exploit this vulnerability, effectively allowing unauthorized access to the router's functionality and potential control over the affected systems. This vulnerability was identified under the identifier ZDI-CAN-20429.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RAX30 1.0.9.92_1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved