Injection Vulnerability in RT-AC88U Download Master by Asus
CVE-2020-29655

7.5HIGH

Key Information:

Vendor

Asus

Vendor
CVE Published:
9 December 2020

What is CVE-2020-29655?

An injection vulnerability exists in the RT-AC88U Download Master prior to version 3.1.0.108, which allows an attacker to manipulate the login page's appearance. Specifically, accessing the URL Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp can lead to the unintended display of the 'productname' parameter's value in the title, enabling potential text injection attacks. This flaw could be exploited to mislead users or facilitate further malicious activities.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.