9.3

CVE-2017-11344

Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asuswrt-merlin ProjectRt-ac5300 Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac5300 Version-
Asuswrt-merlin ProjectRt Ac1900p Firmware Version <= 3.0.0.4.380.7743
Asuswrt-merlin ProjectRt-ac68u Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac68u Version-
Asuswrt-merlin ProjectRt-ac68p Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac68p Version-
Asuswrt-merlin ProjectRt-ac88u Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac88u Version-
Asuswrt-merlin ProjectRt-ac66u Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac66u Version-
Asuswrt-merlin ProjectRt-ac66u B1 Firmware Version <= 3.0.0.4.380.7743
Asuswrt-merlin ProjectRt-ac58u Firmware Version <= 3.0.0.4.380.7485
   Asuswrt-merlin ProjectRt-ac58u Version-
Asuswrt-merlin ProjectRt-ac56u Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac56u Version-
Asuswrt-merlin ProjectRt-ac55u Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-ac55u Version-
Asuswrt-merlin ProjectRt-ac52u Firmware Version <= 3.0.0.4.380.4180
   Asuswrt-merlin ProjectRt-ac52u Version-
Asuswrt-merlin ProjectRt-ac51u Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-ac51u Version-
Asuswrt-merlin ProjectRt-n18u Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-n18u Version-
Asuswrt-merlin ProjectRt-n66u Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-n66u Version-
Asuswrt-merlin ProjectRt-n56u Firmware Version <= 3.0.0.4.378.7177
   Asuswrt-merlin ProjectRt-n56u Version-
Asuswrt-merlin ProjectRt-ac3200 Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac3200 Version-
Asuswrt-merlin ProjectRt-ac3100 Firmware Version <= 3.0.0.4.380.7743
   Asuswrt-merlin ProjectRt-ac3100 Version-
Asuswrt-merlin ProjectRt Ac1200gu Firmware Version <= 3.0.0.4.380.5577
Asuswrt-merlin ProjectRt Ac1200g Firmware Version <= 3.0.0.4.380.3167
Asuswrt-merlin ProjectRt-ac1200 Firmware Version <= 3.0.0.4.380.9880
   Asuswrt-merlin ProjectRt-ac1200 Version-
Asuswrt-merlin ProjectRt-ac53 Firmware Version <= 3.0.0.4.380.9883
   Asuswrt-merlin ProjectRt-ac53 Version-
Asuswrt-merlin ProjectRt-n12hp Firmware Version <= 3.0.0.4.380.2943
   Asuswrt-merlin ProjectRt-n12hp Version-
Asuswrt-merlin ProjectRt-n12hp B1 Firmware Version <= 3.0.0.4.380.3479
Asuswrt-merlin ProjectRt-n12d1 Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-n12d1 Version-
Asuswrt-merlin ProjectRt-n16 Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-n16 Version-
Asuswrt-merlin ProjectRt-n300 Firmware Version <= 3.0.0.4.380.7378
   Asuswrt-merlin ProjectRt-n300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.779
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.