PT-2021-7656 · Asus · Asus Rt-Ac68U
Robert Chen
·
Published
2021-01-18
·
Updated
2023-02-10
·
CVE-2021-37316
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AC68U router firmware versions prior to 3.0.0.4.386.41634
Description
The issue is related to a SQL injection vulnerability in the Cloud Disk feature of the ASUS RT-AC68U router firmware. This vulnerability allows remote attackers to view sensitive information, specifically via the /etc/shadow file. The vulnerability is due to inadequate protection of the SQL query structure.
Recommendations
For versions prior to 3.0.0.4.386.41634, update the firmware to version 3.0.0.4.386.41634 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cloud Disk feature until the update is applied. Avoid using the /etc/shadow file in the affected API endpoint until the issue is resolved.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ac68U