An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

Project Subscriptions

Vendors Products
Asuswrt Subscribe
Gt-ac2900 Subscribe
Gt-ac5300 Subscribe
Gt-ax11000 Subscribe
Rt-ac1200 Subscribe
Rt-ac1200 V2 Subscribe
Rt-ac1200g Subscribe
Rt-ac1200ge Subscribe
Rt-ac1750 Subscribe
Rt-ac1750 B1 Subscribe
Rt-ac1900p Subscribe
Rt-ac3100 Subscribe
Rt-ac3200 Subscribe
Rt-ac51u Subscribe
Rt-ac5300 Subscribe
Rt-ac55u Subscribe
Rt-ac56r Subscribe
Rt-ac56s Subscribe
Rt-ac56u Subscribe
Rt-ac66r Subscribe
Rt-ac66u Subscribe
Rt-ac66u-b1 Subscribe
Rt-ac66u B1 Subscribe
Rt-ac68p Subscribe
Rt-ac68u Subscribe
Rt-ac86u Subscribe
Rt-ac87u Subscribe
Rt-ac88u Subscribe
Rt-acrh12 Subscribe
Rt-acrh13 Subscribe
Rt-ax3000 Subscribe
Rt-ax56u Subscribe
Rt-ax58u Subscribe
Rt-ax88u Subscribe
Rt-ax92u Subscribe
Rt-n10\+d1 Subscribe
Rt-n10e Subscribe
Rt-n14u Subscribe
Rt-n56r Subscribe
Rt-n56u Subscribe
Rt-n600 Subscribe
Rt-n65u Subscribe
Rt-n66r Subscribe
Rt-n66u Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-12892 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:58:18.926Z

Reserved: 2018-12-21T00:00:00

Link: CVE-2018-20334

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-20T01:15:22.357

Modified: 2024-11-21T04:01:15.487

Link: CVE-2018-20334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses