Asus

Asuswrt

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.65%
  • Published 05.08.2022 22:15:11
  • Last modified 21.11.2024 06:53:52

A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a netw...

Exploit
  • EPSS 0.53%
  • Published 20.03.2020 01:15:22
  • Last modified 21.11.2024 04:01:15

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.

Exploit
  • EPSS 3.7%
  • Published 20.03.2020 01:15:22
  • Last modified 21.11.2024 04:01:15

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and g...

Exploit
  • EPSS 1.67%
  • Published 20.03.2020 01:15:22
  • Last modified 21.11.2024 04:01:15

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.

Exploit
  • EPSS 0.95%
  • Published 31.01.2018 20:29:00
  • Last modified 21.11.2024 03:14:58

Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

Exploit
  • EPSS 1.44%
  • Published 31.01.2018 20:29:00
  • Last modified 21.11.2024 03:14:58

Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as...

Exploit
  • EPSS 0.48%
  • Published 31.01.2018 20:29:00
  • Last modified 21.11.2024 03:14:58

Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

Exploit
  • EPSS 90.79%
  • Published 22.01.2018 20:29:00
  • Last modified 21.11.2024 04:09:51

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

Exploit
  • EPSS 90.65%
  • Published 22.01.2018 20:29:00
  • Last modified 21.11.2024 04:09:51

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and lau...