CVE-2021-37316: SQL Injection
Published Feb 3, 2023
·Updated
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
Affected Software
4 affected components
ASUS RT-AC68U Firmware<3.0.0.4.386.41634
ASUS RT-AC68U
All of the following
ASUS RT-AC68U Firmware<3.0.0.4.386.41634
ASUS RT-AC68U
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the SQL injection vulnerability in ASUS RT-AC68U router firmware?
The vulnerability ID for the SQL injection vulnerability in ASUS RT-AC68U router firmware is CVE-2021-37316.
2
What is the severity of CVE-2021-37316?
The severity of CVE-2021-37316 is high with a severity value of 7.5.
3
How can remote attackers exploit CVE-2021-37316?
Remote attackers can exploit CVE-2021-37316 by manipulating input to the Cloud Disk feature to execute arbitrary SQL commands.
4
What is the affected software version of ASUS RT-AC68U router firmware for CVE-2021-37316?
The affected software version of ASUS RT-AC68U router firmware for CVE-2021-37316 is before 3.0.0.4.386.41634.
5
Is the ASUS RT-AC68U router itself vulnerable to CVE-2021-37316?
No, the ASUS RT-AC68U router itself is not vulnerable to CVE-2021-37316.