PT-2018-4956 · Asus · Asus Rp-Ac52
Ian Smith
·
Published
2018-07-13
·
Updated
2019-10-09
·
CVE-2016-6558
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS RP-AC52 access point firmware version 1.0.1.1s and possibly earlier
Description
A command injection issue exists in the apply.cgi web interface, specifically in the
action script parameter. This parameter is used to specify a script for execution when the action mode parameter does not contain a valid state. If the input provided by action script does not match one of the hardcoded options, it will be executed as an argument of either a system() or an eval() call, allowing arbitrary commands to be executed.Recommendations
For firmware version 1.0.1.1s and possibly earlier, consider restricting access to the apply.cgi web interface until a patch is available. As a temporary workaround, avoid using the
action script parameter in the affected web interface to minimize the risk of exploitation.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rp-Ac52