OS Command Injection Vulnerability in ASUS Routers
CVE-2018-9285
9.8CRITICAL
What is CVE-2018-9285?
The Main_Analysis_Content.asp file in the firmware of several ASUS RT-AC series routers allows an attacker to inject OS commands through the pingCNT and destIP fields in the SystemCmd variable. This vulnerability exists in devices running firmware versions prior to specified updates, potentially allowing unauthorized access to the system and execution of arbitrary commands.