CVE-2026-11851: SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11851?
CVE-2026-11851 has a medium severity rating of 5.9 on the CVSS scale.
How do I fix CVE-2026-11851?
To fix CVE-2026-11851, update the ASUS router firmware to the latest version provided by ASUS.
What type of vulnerability is CVE-2026-11851?
CVE-2026-11851 is an SQL Injection vulnerability that affects the web management interface of certain ASUS router models.
Who is affected by CVE-2026-11851?
Remote authenticated users of specific ASUS router models may be affected by CVE-2026-11851.
What can an attacker achieve with CVE-2026-11851?
An attacker can disclose confidential information by sending a crafted request that bypasses existing input validation.