CVE-2026-11851EPSS p40.7%
CVE-2026-11851CVE-2026-11851
Description
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation
Refer to the '
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Scoring
| EPSS | 0.50% probability of exploitation · percentile 40.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-15 |