First published: Fri Feb 03 2023(Updated: )
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS RT-AC68U Firmware | <3.0.0.4.386.41634 | |
ASUS RT-AC68U |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the SQL injection vulnerability in ASUS RT-AC68U router firmware is CVE-2021-37316.
The severity of CVE-2021-37316 is high with a severity value of 7.5.
Remote attackers can exploit CVE-2021-37316 by manipulating input to the Cloud Disk feature to execute arbitrary SQL commands.
The affected software version of ASUS RT-AC68U router firmware for CVE-2021-37316 is before 3.0.0.4.386.41634.
No, the ASUS RT-AC68U router itself is not vulnerable to CVE-2021-37316.