go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS Control Center - SQL Injection

TVN ID TVN-202203002
CVE ID CVE-2022-26669
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products ASUS Control Center v1.4.2.5
Description ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.
Solution Update version to 1.4.3.2
Credit Cyku Hong (DEVCORE)
Public Date 2022-04-26
Top