SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-11851

MEDIUM · CVSS 5.9 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Certain ASUS router models are vulnerable to SQL injection through their web management interface, allowing remote authenticated users to exploit this flaw and disclose sensitive information by sending specially crafted requests that circumvent input validation. Organizations using affected ASUS routers should prioritize this vulnerability to mitigate potential data breaches and protect user confidentiality. It is essential to apply the recommended firmware updates as outlined in the ASUS Security Advisory.

CVE
CVE-2026-11851
Severity
MEDIUM
CVSS
5.9
EPSS
0.37%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the '  Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.