ASMAX AR 804 gu Web Management Console Injection Vulnerability
2 Jun. 2009
Summary
ASMAX 804 gu router is a SOHO class device. It provides ADSL / WiFi / Ethernet interfaces. There is an *unauthenticated* maintenance script (named 'script') in /cgi-bin/ directory of the web management interface. When 'system' paramether is passed to the script it allows running OS shell commands as root.