An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
References
Link | Resource |
---|---|
https://starlabs.sg/advisories/18-20334/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2020-03-20 01:15
Updated : 2024-02-04 21:00
NVD link : CVE-2018-20334
Mitre link : CVE-2018-20334
CVE.ORG link : CVE-2018-20334
JSON object : View
Products Affected
asus
- rt-ac55u
- rt-ac56s
- rt-ac86u
- rt-ac1200g
- asuswrt
- rt-n14u
- rt-n16
- rt-ac68p
- rt-ac56r
- rt-ac66r
- rt-ac68u
- rt-n66r
- rt-ac66u-b1
- rt-n56u
- rt-ac88u
- rt-ac3100
- rt-ax3000
- gt-ac2900
- rt-ac1900p
- rt-ac5300
- rt-ac51u
- rt-ac1200ge
- rt-n19
- rt-ax58u
- rt-ac1200
- rt-ac3200
- rt-ac1200_v2
- rt-n66u
- rt-ac1750_b1
- rt-n65u
- rt-acrh13
- rt-n56r
- rt-n10\+d1
- rt-ax56u
- rt-ac1750
- rt-ax92u
- rt-n10e
- rt-ac66u
- rt-n600
- rt-ac87u
- gt-ac5300
- rt-ac56u
- rt-ac66u_b1
- rt-acrh12
- rt-g32
- rt-ax88u
- gt-ax11000
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')