CVE-2016-6558: The ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, is vulnerable to command injection
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the actionscript parameter. The actionscript parameter specifies a script to be executed if the actionmode parameter does not contain a valid state. If the input provided by actionscript does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6558?
CVE-2016-6558 has a severity rating that indicates a high risk of exploitation due to the command injection vulnerability.
How do I fix CVE-2016-6558?
To fix CVE-2016-6558, upgrade the firmware of the ASUS RP-AC52 access point to a version later than 1.0.1.1s.
Which devices are affected by CVE-2016-6558?
CVE-2016-6558 specifically affects the ASUS RP-AC52 access point running firmware version 1.0.1.1s and potentially earlier versions.
What impact does CVE-2016-6558 pose?
CVE-2016-6558 poses a risk of unauthorized command execution, allowing attackers to execute arbitrary commands on the affected device.
Is CVE-2016-6558 related to other ASUS devices?
CVE-2016-6558 only affects the ASUS RP-AC52 and does not impact other ASUS devices like the EA-N66 or RP-N12, which are not vulnerable.