PT-2017-3654 · Asus · Asus Gt-Ac5300+10

David Maciejak

·

Published

2017-12-23

·

Updated

2020-11-13

·

CVE-2018-9285

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ASUS RT-AC66U versions prior to 3.0.0.4.384 10007 ASUS RT-AC68U versions prior to 3.0.0.4.384 10007 ASUS RT-AC86U versions prior to 3.0.0.4.384 10007 ASUS RT-AC88U versions prior to 3.0.0.4.384 10007 ASUS RT-AC1900 versions prior to 3.0.0.4.384 10007 ASUS RT-AC2900 versions prior to 3.0.0.4.384 10007 ASUS RT-AC3100 versions prior to 3.0.0.4.384 10007 ASUS RT-N18U versions prior to 3.0.0.4.382.39935 ASUS RT-AC87U versions prior to 3.0.0.4.382.50010 ASUS RT-AC3200 versions prior to 3.0.0.4.382.50010 ASUS RT-AC5300 versions prior to 3.0.0.4.384.20287
Description: The issue allows for OS command injection via the pingCNT and destIP fields of the SystemCmd variable in the Main Analysis Content.asp page of the /apply.cgi component. This can be exploited by sending HTTP requests, enabling a remote attacker to execute arbitrary commands.
Recommendations: For ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices, update to version 3.0.0.4.384 10007 or later. For RT-N18U devices, update to version 3.0.0.4.382.39935 or later. For RT-AC87U and RT-AC3200 devices, update to version 3.0.0.4.382.50010 or later. For RT-AC5300 devices, update to version 3.0.0.4.384.20287 or later. As a temporary workaround, consider restricting access to the Main Analysis Content.asp page and the SystemCmd variable to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00785
CVE-2018-9285

Affected Products

Asus Rt-Ac1900
Asus Rt-Ac2900
Asus Rt-Ac3100
Asus Rt-Ac3200
Asus Gt-Ac5300
Asus Rt-Ac66U
Asus Rt-Ac68U
Asus Rt-Ac86U
Asus Rt-Ac87U
Asus Rt-A88U
Asus Rt-N18U