First published: Mon May 13 2019(Updated: )
System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ac3200 Firmware | =3.0.0.4.382.50010 | |
ASUS RT-AC3200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14714 is a system command injection vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010.
CVE-2018-14714 has a severity rating of 9.8 (critical).
CVE-2018-14714 allows attackers to execute system commands via the "load_script" URL parameter.
To fix CVE-2018-14714, update your ASUS RT-AC3200 router to a version that has the vulnerability patched.
You can find more information about CVE-2018-14714 at the following reference: https://blog.securityevaluators.com/asus-routers-overflow-with-vulnerabilities-b111bc1c8eb8