Company
Date Published
Author
Paul Gerste, Thomas Chauchefoin, Stefan Schiller
Word count
1793
Language
English
Hacker News points
None

Summary

The text discusses vulnerabilities discovered by members of a Vulnerability Research team during the Pwn2Own Toronto 2022 competition, which were later reported to vendors and addressed through security updates. The team found two LAN-side vulnerabilities on the NETGEAR RAX30 router and one WAN-side vulnerability on both the NETGEAR RAX30 and Synology RT6600ax routers. They also discovered a buffer overflow vulnerability in the telnet service of the NETGEAR RAX30, which could be exploited to control the instruction pointer and execute arbitrary system commands. The vulnerabilities were reported to ZDI (Zero Day Initiative) and addressed through patches by vendors. The team's findings demonstrate the importance of security testing on consumer devices and provide valuable insights into the technical details of these vulnerabilities.