8.5
CVSSv2

CVE-2013-5948

Published: 22/04/2014 Updated: 30/06/2016
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware prior to 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter).

Vulnerable Product Search on Vulmon Subscribe to Product

t-mobile tm-ac1900 3.0.0.4.376_3169

asus rt-ac68u_firmware 3.0.0.4.374_4561

asus rt-ac68u_firmware 3.0.0.4.374_4887

asus rt-ac68u_firmware 3.0.0.4.374.4755

asus rt-ac68u -

Exploits

# Exploit Title: Asus RT56U Remote Command Injection # Date: 05/05/2013 # Exploit Author: drone (@dronesec) # Vendor Homepage: asuscom # Version: <= 3004360 (latest) Device Details: ============== Router information: wwwasuscom/Networking/RTN56U/ Firmware: wwwasuscom/Networking/RTN56U/#support_Download_30 Vulnerability ...