vendor:
RT56U
by:
drone (@dronesec)
7,5
CVSS
HIGH
Remote Command Injection
78
CWE
Product Name: RT56U
Affected Version From: <= 3.0.0.4.360 (latest)
Affected Version To: <= 3.0.0.4.360 (latest)
Patch Exists: YES
Related CWE: N/A
CPE: o:asus:rt56u
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Asus RT56U Remote Command Injection
Insufficient (or rather, a complete lack thereof) input sanitization leads to the injection of shell commands. It's possible to upload and execute a backdoor.
Mitigation:
Input validation should be used to detect and reject malicious input.