vendor:
RT-N66U
by:
N/A
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: RT-N66U
Affected Version From: 3.0.0.4.376_1071-g8696125
Affected Version To: 3.0.0.4.376_1071-g8696125
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
ASUSWRT 3.0.0.4.376_1071 LAN Backdoor Command Execution
A service called 'infosvr' listens on port 9999 on the LAN bridge. Normally this service is used for device discovery using the 'ASUS Wireless Router Device Discovery Utility', but this service contains a feature that allows an unauthenticated user on the LAN to execute commands <= 237 bytes as root. Source code is in asuswrt/release/src/router/infosvr. 'iboxcom.h' is in asuswrt/release/src/router/shared.
Mitigation:
Disable the service or restrict access to it.