ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
No PoCs from references.
- https://github.com/attilaszia/linux-iot-cves
- https://github.com/winmt/winmt