- EPSS 91.05%
- Veröffentlicht 08.01.2015 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass au...
CVE-2014-2718
- EPSS 0.24%
- Veröffentlicht 04.11.2014 22:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, wh...
CVE-2014-2925
- EPSS 0.34%
- Veröffentlicht 22.04.2014 13:06:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter...
CVE-2014-2719
- EPSS 0.31%
- Veröffentlicht 22.04.2014 13:06:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code.
CVE-2013-5948
- EPSS 43.23%
- Veröffentlicht 22.04.2014 13:06:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (...
CVE-2013-1813
- EPSS 0.03%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
CVE-2011-2716
- EPSS 0.71%
- Veröffentlicht 03.07.2012 16:40:30
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.