ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
2023-06-02T11:15:10.510
2024-11-21T07:55:50.027
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | rt-ac86u_firmware | 3.0.0.4.386.51255 | Yes |
Hardware | asus | rt-ac86u | - | No |