An issue was discovered in ASUSWRT When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

Source: CVE-2018-20334

