Description
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation
Refer to the ' 
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in an SQL command (CWE-89) was discovered in the web management interface of certain ASUS routers. The flaw allows an authenticated remote user to craft a request that bypasses input validation and injects malicious SQL, enabling the disclosure of confidential information stored in the router’s database. The primary impact is information disclosure with remote authenticated access; no code execution or denial of service is stated in the advisory.

Affected Systems

Affected systems include ASUS routers utilizing firmware versions 3.0.0.4_386_series, 3.0.0.4_388_series, and 3.0.0.6_102_series, and the vulnerability is an SQL injection caused by inadequate neutralization of special elements in an SQL command within the web management interface of certain ASUS routers. An attacker who is already authenticated to the router can craft a request that maps to CWE-89.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate risk, and the EPSS score of less than 1% suggests that exploit activity is currently low. Because the attack requires prior authentication, the opportunity for exploitation is limited to users who can log into the router’s web interface. This vulnerability is not in the CISA KEV catalog, indicating no known widespread exploitation.

Generated by OpenCVE AI on July 31, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware from ASUS that fixes the SQL injection issue.
  • Disable remote management or limit web interface access to local network or a trusted IP whitelist.
  • Monitor router logs and network traffic for any unusual or repeated attempts to send malformed SQL queries.

Generated by OpenCVE AI on July 31, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in ASUS Router Web Management Interface Allows Information Disclosure

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in ASUS Router Web Management Interface Allows Information Disclosure

Sat, 25 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title SQL Injection via Web Interface Allowing Information Disclosure on ASUS Routers

Wed, 22 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title SQL Injection via Web Interface Allowing Information Disclosure on ASUS Routers

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in ASUS Router Web Management Allows Remote Authenticated Disclosure

Thu, 16 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in ASUS Router Web Management Allows Remote Authenticated Disclosure

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the '  Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus router
Weaknesses CWE-89
CPEs cpe:2.3:a:asus:router:asuswrt_3.0.0.4_386_series:*:*:*:*:*:*:*
cpe:2.3:a:asus:router:asuswrt_3.0.0.4_388_series:*:*:*:*:*:*:*
cpe:2.3:a:asus:router:asuswrt_3.0.0.6_102_series:*:*:*:*:*:*:*
Vendors & Products Asus
Asus router
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-15T12:35:35.495Z

Reserved: 2026-06-10T08:22:42.915Z

Link: CVE-2026-11851

cve-icon Vulnrichment

Updated: 2026-07-15T12:35:22.131Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')