go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS WiFi Router - OS Command Injection

TVN ID TVN-202404006
CVE ID CVE-2024-1655
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products ExpertWiFi EBM63 firmware before 3.0.0.6.102_32645
ExpertWiFi EBM68 firmware before 3.0.0.6.102_44384
RT-AX57 Go firmware before 3.0.0.6.102_22188
Description Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.
Solution Update ExpertWiFi EBM63 firmware to 3.0.0.6.102_32645 or later version
Update ExpertWiFi EBM68 firmware to 3.0.0.6.102_44384 or later version
Update RT-AX57 Go firmware to 3.0.0.6.102_22188 or later version
Credit William Shi
Public Date 2024-04-15
Top