PT-2024-4605 · Asus · Asus Rt-N12+ B1
Published
2024-04-26
·
Updated
2024-07-03
·
CVE-2024-28328
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
ASUS RT-N12+ B1 version (affected versions not specified)
Description:
The issue is related to a lack of data sanitization on the administrative level, allowing for the exploitation of a CSV injection vulnerability. This vulnerability enables a remote attacker to execute arbitrary commands by injecting malicious input through the
client name parameter. The vulnerability can be triggered when exporting data to CSV format, potentially allowing the execution of injected commands or formulas in a different user session.Recommendations:
As a temporary workaround, consider restricting access to the
client name parameter to minimize the risk of exploitation.
Avoid using the client name parameter in the affected router until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-N12+ B1