go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS Download Master - OS Command Injection

TVN ID TVN-202406007
CVE ID CVE-2024-31162
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products Download Master version 3.1.0.113 and earlier.
Description The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
Solution Update to version 3.1.0.114 or later.
Credit Howard McGreehan
Public Date 2024-06-14
Top