go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS RT-AC86U - Command Injection

TVN ID TVN-202305004
CVE ID CVE-2023-28702
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products ASUS RT-AC86U v3.0.0.4.386.51255
Description ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
Solution Update version to lastest
Credit Tmotfl (Xingyu Xu)
Public Date 2023-05-30
Top