Description
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32345 | ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7146-ef92a-1.html |
|
History
Wed, 08 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-01-08T20:08:43.251Z
Reserved: 2023-03-21T00:00:00.000Z
Link: CVE-2023-28702
Updated: 2024-08-02T13:43:23.680Z
Status : Modified
Published: 2023-06-02T11:15:10.510
Modified: 2024-11-21T07:55:50.027
Link: CVE-2023-28702
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD