cbcvebase.
CVE-2023-28702
published 2023-06-02

CVE-2023-28702: ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.

Affected

2 ranges
VendorProductVersion rangeFixed in
asusrt-ac86u
asusrt-ac86u_firmware