Junglewise Threat Intelligence

CVE-2026-11851: ASUS Router SQL injection in web management interface

CVE-2026-11851 · Severity: info · CVSS 5.9 · Published 2026-07-15

Vendors: ASUS.

Executive brief

A security vulnerability exists in the web management interface of several ASUS router models. An attacker with administrative credentials could use a specially crafted request to bypass security checks and access sensitive information stored on the device. This could lead to the exposure of confidential configuration data or other private information managed by the router.

Technical details

An SQL injection vulnerability (CWE-89) exists within the web management interface of ASUS router firmware versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102. The flaw stems from improper neutralization of special elements in SQL commands, allowing a remote authenticated user with high privileges (PR:H) to bypass input validation. By sending a crafted request, an attacker can execute arbitrary SQL queries to disclose confidential information from the underlying database. While the attack requires authentication and high privileges, it can be executed over the network. ASUS has addressed this in their security updates; users are advised to update to the latest firmware versions.

Affected products

  • ASUS Router Firmware (ASUSWRT) 3.0.0.4_386 series
  • ASUS Router Firmware (ASUSWRT) 3.0.0.4_388 series
  • ASUS Router Firmware (ASUSWRT) 3.0.0.6_102 series

Timeline

  • 2026-07-14: disclosed: CVE published by ASUS CNA
  • 2026-07-15: advisory: NVD publication date

References