peter bassill · operator
$ cve CVE-2016-6558 JSON

CVE-2016-6558

9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.5% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2018-07-13
Last modified2026-06-17

Affected (14)

VendorProduct
asusea-n66
asusea-n66 firmware
asusrp-ac52
asusrp-ac52 firmware
asusrp-ac56
asusrp-ac56 firmware
asusrp-n12
asusrp-n12 firmware
asusrp-n14
asusrp-n14 firmware
asusrp-n53
asusrp-n53 firmware
asuswmp-n12
asuswmp-n12 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD