CVE-2024-28328: Command Injection
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28328?
CVE-2024-28328 is considered a high-severity vulnerability due to its potential to execute arbitrary commands via CSV injection.
How do I fix CVE-2024-28328?
To fix CVE-2024-28328, ensure your Asus RT-N12+ router is updated to the latest firmware provided by Asus.
Who is affected by CVE-2024-28328?
CVE-2024-28328 affects users of the Asus RT-N12+ router who have administrator access.
What actions should I take if I cannot update my Asus RT-N12+ router to fix CVE-2024-28328?
If you cannot update, limit administrator access and avoid exporting client names to CSV to mitigate CVE-2024-28328 risks.
What is the impact of CVE-2024-28328 on users?
The impact of CVE-2024-28328 includes potential unauthorized command execution, which can compromise user data and router security.