An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/efchatz/easy-exploits