Vulnerability Description
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Rp-Ac52 Firmware | <= 1.0.1.1s |
| Asus | Rp-Ac52 | - |
| Asus | Ea-N66 Firmware | - |
| Asus | Ea-N66 | - |
| Asus | Rp-N12 Firmware | - |
| Asus | Rp-N12 | - |
| Asus | Rp-N14 Firmware | - |
| Asus | Rp-N14 | - |
| Asus | Rp-N53 Firmware | - |
| Asus | Rp-N53 | - |
| Asus | Rp-Ac56 Firmware | - |
| Asus | Rp-Ac56 | - |
| Asus | Wmp-N12 Firmware | - |
| Asus | Wmp-N12 | - |
Related Weaknesses (CWE)
References
- https://www.kb.cert.org/vuls/id/763843Third Party AdvisoryUS Government Resource
- https://www.securityfocus.com/bid/93596Third Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/763843Third Party AdvisoryUS Government Resource
- https://www.securityfocus.com/bid/93596Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-6558?
CVE-2016-6558 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The a...
How severe is CVE-2016-6558?
CVE-2016-6558 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6558?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Rp-Ac52 Firmware, Asus Rp-Ac52, Asus Ea-N66 Firmware, Asus Ea-N66, Asus Rp-N12 Firmware.