Synology-SA-17:30 Broadpwn

Publish Time: 2017-07-14 00:00:00 UTC+8

Last Updated: 2017-09-19 13:39:51 UTC+8

Severity
Critical
Status
Resolved

Abstract

CVE-2017-9417 could allow remote attackers to cause a denial of service attack or arbitrary code execution on the vulnerable server.

To prevent suffering an attack, should ensure that the device is connected to a trusted WiFi network on client mode.

Severity

Affected

  • Products
    • SRM 1.1
  • Models
    • RT1900ac

Description

Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

Mitigation

None

Update Availability

To fix the security issue, please update SRM 1.1 to 1.1.4-6509-03 or above.

Reference