PT-2021-7656 · Asus · Asus Rt-Ac68U

Robert Chen

·

Published

2021-01-18

·

Updated

2023-02-10

·

CVE-2021-37316

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASUS RT-AC68U router firmware versions prior to 3.0.0.4.386.41634
Description The issue is related to a SQL injection vulnerability in the Cloud Disk feature of the ASUS RT-AC68U router firmware. This vulnerability allows remote attackers to view sensitive information, specifically via the /etc/shadow file. The vulnerability is due to inadequate protection of the SQL query structure.
Recommendations For versions prior to 3.0.0.4.386.41634, update the firmware to version 3.0.0.4.386.41634 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cloud Disk feature until the update is applied. Avoid using the /etc/shadow file in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-01046
CVE-2021-37316

Affected Products

Asus Rt-Ac68U