Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-7479 | A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed. |
No history.
Subscriptions
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T01:36:28.511Z
Reserved: 2016-08-03T00:00:00.000Z
Link: CVE-2016-6558
No data.
Status : Modified
Published: 2018-07-13T20:29:00.847
Modified: 2026-06-17T00:51:22.873
Link: CVE-2016-6558
No data.
OpenCVE Enrichment
No data.
-
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
EUVD