The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter).
CPE | Name | Operator | Version |
---|---|---|---|
rt-ac68u_firmware | eq | 3.0.0.4.374.4755 | |
rt-ac68u_firmware | eq | 3.0.43744561 | |
rt-ac68u_firmware | eq | 3.0.43744887 | |
tm-ac1900 | eq | 3.0.43763169 |