CVE-2018-14714: Command Injection
Published May 13, 2019
·Updated
System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "loadscript" URL parameter.
Affected Software
2 affected components
ASUS Rt-ac3200 Firmware=3.0.0.4.382.50010
ASUS RT-AC3200
Event History
May 13, 2019
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
Description
Frequently Asked Questions
1
What is CVE-2018-14714?
CVE-2018-14714 is a system command injection vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010.
2
What is the severity of CVE-2018-14714?
CVE-2018-14714 has a severity rating of 9.8 (critical).
3
How does CVE-2018-14714 impact ASUS RT-AC3200 version 3.0.0.4.382.50010?
CVE-2018-14714 allows attackers to execute system commands via the "load_script" URL parameter.
4
How can I fix CVE-2018-14714?
To fix CVE-2018-14714, update your ASUS RT-AC3200 router to a version that has the vulnerability patched.
5
Where can I find more information about CVE-2018-14714?
You can find more information about CVE-2018-14714 at the following reference: https://blog.securityevaluators.com/asus-routers-overflow-with-vulnerabilities-b111bc1c8eb8