Rewterz

Rewterz Threat Advisory – CVE-2020-5384 – RSA MFA Agent for Microsoft Windows security bypass

August 5, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-4481 – IBM UrbanCode Deploy XML external entity injection

August 6, 2020

Rewterz Threat Advisory – NETGEAR R6700v3 code execution

Severity

Medium

Analysis Summary

NETGEAR R6700v3 could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the the handling of string table file uploads. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Gain Access
  • Execute arbitrary code 

Affected Vendors

NETGEAR

Affected Products

NETGEAR R6700v3 1.0.4.97

Remediation

NETGEAR strongly recommends that you download the latest firmware as soon as possible.

https://kb.netgear.com/000062126/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R6700v3-PSV-2020-0189

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.