AVM FRITZ!OS prior to 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote malicious users to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
avm fritz\\! os |