Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation
Refer to the '
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.asus.com/security-advisory/ |
Configurations
No configuration.
History
15 Jul 2026, 02:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 02:18
Updated : 2026-07-15 16:24
NVD link : CVE-2026-11851
Mitre link : CVE-2026-11851
CVE.ORG link : CVE-2026-11851
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
