← back
CVE-2024-31162

ASUS Download Master - OS Command Injection

CVSS 7.2 HIGHEPSS 0.6%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Jun 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
ASUS · Download Master

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →