CVE-2018-14714

5 documents4 sources
Severity
9.8CRITICAL
EPSS
81.0%
top 0.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 13
Latest updateSep 25

Description

System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDasus/rt-ac3200_firmware3.0.0.4.382.50010

🔴Vulnerability Details

2
GHSA
GHSA-q682-vx5h-w8xw: System command injection in appGet2022-05-24
CVEList
CVE-2018-14714: System command injection in appGet2019-05-13

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS ASUS RT-AC3200 Command Injection via load_script Hook in appGet.cgi (CVE-2018-14714)2025-09-25
Suricata
ET EXPLOIT ASUSWRT Command Injection via load_script Hook in appGet.cgi (CVE-2018-14714)2025-07-10
CVE-2018-14714 (CRITICAL CVSS 9.8) | System command injection in appGet. | cvebase.io