Injection Vulnerability in RT-AC88U Download Master by Asus
CVE-2020-29655
7.5HIGH
Summary
An injection vulnerability exists in the RT-AC88U Download Master prior to version 3.1.0.108, which allows an attacker to manipulate the login page's appearance. Specifically, accessing the URL Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp can lead to the unintended display of the 'productname' parameter's value in the title, enabling potential text injection attacks. This flaw could be exploited to mislead users or facilitate further malicious activities.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved