Injection Vulnerability in RT-AC88U Download Master by Asus
CVE-2020-29655
7.5HIGH
What is CVE-2020-29655?
An injection vulnerability exists in the RT-AC88U Download Master prior to version 3.1.0.108, which allows an attacker to manipulate the login page's appearance. Specifically, accessing the URL Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp can lead to the unintended display of the 'productname' parameter's value in the title, enabling potential text injection attacks. This flaw could be exploited to mislead users or facilitate further malicious activities.