CVE-2024-12912
HIGH EXPLOITEDASUS Router 3.0.0.4_382-3.0.0.6_102 - OS Command Injection in AiCloud
Title source: llmExploitation Summary
CVE-2024-12912 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including murrez.
AI-analyzed exploit summary The repository contains a functional Go-based exploit for CVE-2024-12912, targeting ASUS AiCloud/AsusWRT devices. It chains two vulnerabilities (SETROOTCERTIFICATE and APPLYAPP) to achieve remote code execution by writing a malicious script to /etc/cert.pem.1 and executing it via RC_SERVICE.
Description
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
Exploits (1)
The repository contains a functional Go-based exploit for CVE-2024-12912, targeting ASUS AiCloud/AsusWRT devices. It chains two vulnerabilities (SETROOTCERTIFICATE and APPLYAPP) to achieve remote code execution by writing a malicious script to /etc/cert.pem.1 and executing it via RC_SERVICE.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H