ASUS Routers SQL Injection Vulnerability in Web Management Interface

Vulnerability

A SQL injection vulnerability has been identified in the web management interface of certain ASUS router models. This issue allows remote authenticated users to bypass existing input validation and disclose confidential information by sending crafted requests. The vulnerability arises from improper neutralization of special elements used in SQL commands.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of confidential information.

Remediation

Users are advised to update to the latest version of the ASUS router firmware. Instructions for updating can be found on the ASUS Security Advisory page.

Added: Jul 15, 2026, 3:27 AM
Updated: Jul 15, 2026, 3:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.