PT-2018-4956 · Asus · Asus Rp-Ac52

Ian Smith

·

Published

2018-07-13

·

Updated

2019-10-09

·

CVE-2016-6558

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS RP-AC52 access point firmware version 1.0.1.1s and possibly earlier
Description A command injection issue exists in the apply.cgi web interface, specifically in the action script parameter. This parameter is used to specify a script for execution when the action mode parameter does not contain a valid state. If the input provided by action script does not match one of the hardcoded options, it will be executed as an argument of either a system() or an eval() call, allowing arbitrary commands to be executed.
Recommendations For firmware version 1.0.1.1s and possibly earlier, consider restricting access to the apply.cgi web interface until a patch is available. As a temporary workaround, avoid using the action script parameter in the affected web interface to minimize the risk of exploitation.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6558

Affected Products

Asus Rp-Ac52