Impact
Improper neutralization of special elements in an SQL command (CWE-89) was discovered in the web management interface of certain ASUS routers. The flaw allows an authenticated remote user to craft a request that bypasses input validation and injects malicious SQL, enabling the disclosure of confidential information stored in the router’s database. The primary impact is information disclosure with remote authenticated access; no code execution or denial of service is stated in the advisory.
Affected Systems
Affected systems include ASUS routers utilizing firmware versions 3.0.0.4_386_series, 3.0.0.4_388_series, and 3.0.0.6_102_series, and the vulnerability is an SQL injection caused by inadequate neutralization of special elements in an SQL command within the web management interface of certain ASUS routers. An attacker who is already authenticated to the router can craft a request that maps to CWE-89.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate risk, and the EPSS score of less than 1% suggests that exploit activity is currently low. Because the attack requires prior authentication, the opportunity for exploitation is limited to users who can log into the router’s web interface. This vulnerability is not in the CISA KEV catalog, indicating no known widespread exploitation.
OpenCVE Enrichment