ASUS RT-AC86U - Command injection vulnerability - 3
Description
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ASUS RT-AC86U's Traffic Analyzer legacy Statistic function lacks input sanitization, allowing authenticated command injection with high impact.
Vulnerability
ASUS RT-AC86U firmware versions prior to 3.0.0.4.386_51915 contain a command injection flaw in the Traffic Analyzer legacy Statistic function (wanStat_detail). The function fails to properly filter special characters in input parameters, enabling an attacker who has already obtained regular user credentials to inject arbitrary operating system commands [1].
Exploitation
An attacker must be a remote user with a valid regular-privilege account on the router. No additional privileges or physical access are required. By sending a crafted HTTP request to the vulnerable wanStat_detail endpoint with malicious payloads in the unsanitized parameters, the attacker can execute arbitrary shell commands on the underlying system [1].
Impact
Successful command injection allows the attacker to execute arbitrary commands as a high-privilege user, leading to full compromise of the device. This can result in complete loss of confidentiality (reading sensitive data), integrity (modifying system files or configurations), and availability (disrupting services or causing denial of service) [1].
Mitigation
ASUS released firmware version 3.0.0.4.386_51915 to fix this vulnerability. Affected users should update their RT-AC86U routers to this or a later patched version immediately. No official workaround is available apart from upgrading [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.