Injection Vulnerability in RT-AC88U Download Master by Asus
CVE-2020-29655

7.5HIGH

Key Information:

Vendor
Asus
Vendor
CVE Published:
9 December 2020

Summary

An injection vulnerability exists in the RT-AC88U Download Master prior to version 3.1.0.108, which allows an attacker to manipulate the login page's appearance. Specifically, accessing the URL Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp can lead to the unintended display of the 'productname' parameter's value in the title, enabling potential text injection attacks. This flaw could be exploited to mislead users or facilitate further malicious activities.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.