CVE-2016-6558
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.
Published:Jul 13, 2018
Last Modified:Nov 21, 2024
EPS:Jul 13, 2018
EPSS Score:0.04241
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Asus
Product
Ea-n66
Asus
Ea-n66
Vendor
Asus
Product
Ea-n66 Firmware
Asus
Ea-n66 Firmware
Vendor
Asus
Product
Rp-ac52
Asus
Rp-ac52
Vendor
Asus
Product
Rp-ac52 Firmware
Asus
Rp-ac52 Firmware
Vendor
Asus
Product
Rp-ac56
Asus
Rp-ac56
Vendor
Asus
Product
Rp-ac56 Firmware
Asus
Rp-ac56 Firmware
Vendor
Asus
Product
Rp-n12
Asus
Rp-n12
Vendor
Asus
Product
Rp-n12 Firmware
Asus
Rp-n12 Firmware
Vendor
Asus
Product
Rp-n14
Asus
Rp-n14
Vendor
Asus
Product
Rp-n14 Firmware
Asus
Rp-n14 Firmware
Vendor
Asus
Product
Rp-n53
Asus
Rp-n53
Vendor
Asus
Product
Rp-n53 Firmware
Asus
Rp-n53 Firmware
Vendor
Asus
Product
Wmp-n12
Asus
Wmp-n12
Vendor
Asus
Product
Wmp-n12 Firmware
Asus
Wmp-n12 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
