SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-6558

A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter.

CRITICAL 9.8EPSS 3.55%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.55% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
asus/rp-ac52 firmware · asus/ea-n66 firmware · asus/rp-n12 firmware · asus/rp-n14 firmware · asus/rp-n53 firmware · asus/rp-ac56 firmware · asus/wmp-n12 firmware
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.