ASUS Router
- >= 3.0.0.4_386, < 3.0.0.4_387
- >= 3.0.0.4_388, < 3.0.0.4_389
- >= 3.0.0.6_102, < 3.0.0.6_103
A SQL injection vulnerability has been identified in the web management interface of certain ASUS router models. This issue allows remote authenticated users to bypass existing input validation and disclose confidential information by sending crafted requests. The vulnerability arises from improper neutralization of special elements used in SQL commands.
Exploitation of this vulnerability could lead to unauthorized disclosure of confidential information.
Users are advised to update to the latest version of the ASUS router firmware. Instructions for updating can be found on the ASUS Security Advisory page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.