CVE-2018-15887: OS Command Injection
MainAnalysisContent.asp in ASUS DSL-N12EC1 1.1.2.3345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, such as shell metacharacters in the destIP parameter of a cmdMethod=ping request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15887?
CVE-2018-15887 is a vulnerability in ASUS DSL-N12E_C1 1.1.2.3_345 that allows authenticated remote command execution.
How severe is CVE-2018-15887?
CVE-2018-15887 has a severity rating of 8.8 (high).
What software is affected by CVE-2018-15887?
ASUS DSL-N12E_C1 1.1.2.3_345 firmware is affected by CVE-2018-15887.
How can an attacker exploit CVE-2018-15887?
An attacker can exploit CVE-2018-15887 by executing arbitrary OS commands using service parameters, such as shell metacharacters in the destIP parameter of a cmdMethod=ping request.
Is ASUS DSL-N12E_C1 vulnerable to CVE-2018-15887?
Yes, ASUS DSL-N12E_C1 with 1.1.2.3_345 firmware is vulnerable to CVE-2018-15887.