vendor:
DSL-N12E_C1
by:
Fakhri Zulkifli
8.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: DSL-N12E_C1
Affected Version From: 1.1.2.3_345
Affected Version To: 1.1.2.3_345
Patch Exists: YES
Related CWE: N/A
CPE: h:asus:dsl-n12e_c1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
ASUS DSL-N12E_C1 1.1.2.3_345 – Remote Command Execution
A vulnerability in ASUS DSL-N12E_C1 1.1.2.3_345 allows an attacker to execute arbitrary commands on the device by sending a specially crafted HTTP request. The vulnerability exists due to insufficient validation of user-supplied input in the ‘cmdMethod’ parameter of the ‘Main_Analysis_Content.asp’ page. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable device. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the vulnerable device.
Mitigation:
Upgrade to the latest version of ASUS DSL-N12E_C1 1.1.2.3_345 or later.