CVE-2022-26376
- EPSS 0.65%
- Veröffentlicht 05.08.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 06:53:52
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a netw...
CVE-2018-20333
- EPSS 0.53%
- Veröffentlicht 20.03.2020 01:15:22
- Zuletzt bearbeitet 21.11.2024 04:01:15
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
- EPSS 3.7%
- Veröffentlicht 20.03.2020 01:15:22
- Zuletzt bearbeitet 21.11.2024 04:01:15
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and g...
CVE-2018-20335
- EPSS 1.67%
- Veröffentlicht 20.03.2020 01:15:22
- Zuletzt bearbeitet 21.11.2024 04:01:15
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
CVE-2017-15654
- EPSS 0.95%
- Veröffentlicht 31.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:58
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.
CVE-2017-15655
- EPSS 1.44%
- Veröffentlicht 31.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:58
Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as...
CVE-2017-15656
- EPSS 0.48%
- Veröffentlicht 31.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:58
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
- EPSS 90.79%
- Veröffentlicht 22.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:51
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.
- EPSS 90.65%
- Veröffentlicht 22.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:51
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and lau...