First published: Fri Apr 26 2024(Updated: )
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus RP-N12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28328 is considered a high-severity vulnerability due to its potential to execute arbitrary commands via CSV injection.
To fix CVE-2024-28328, ensure your Asus RT-N12+ router is updated to the latest firmware provided by Asus.
CVE-2024-28328 affects users of the Asus RT-N12+ router who have administrator access.
If you cannot update, limit administrator access and avoid exporting client names to CSV to mitigate CVE-2024-28328 risks.
The impact of CVE-2024-28328 includes potential unauthorized command execution, which can compromise user data and router security.