Vulnerabilities > Asus

DATE CVE VULNERABILITY TITLE RISK
2021-04-06 CVE-2021-28176 Classic Buffer Overflow vulnerability in Asus products
The DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability.
network
low complexity
asus CWE-120
4.9
2021-04-06 CVE-2021-28175 Classic Buffer Overflow vulnerability in Asus products
The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability.
network
low complexity
asus CWE-120
4.9
2021-03-31 CVE-2021-26943 Unspecified vulnerability in Asus Ux360Ca Bios 303
The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory locations, including SMRAM, and execute arbitrary code in the SMM (issue 3 of 3).
local
low complexity
asus
8.2
2021-02-19 CVE-2021-27404 Open Redirect vulnerability in Asus Askey Rtf8115Vw Firmware Brsvg11.11Rtftef001V6.54V014
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
network
low complexity
asus CWE-601
6.1
2021-02-19 CVE-2021-27403 Cross-site Scripting vulnerability in Asus Askey Rtf8115Vw Firmware Brsvg11.11Rtftef001V6.54V014
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
network
low complexity
asus CWE-79
6.1
2021-02-05 CVE-2021-3229 Unspecified vulnerability in Asus Rt-Ax3000 Firmware 3.0.0.4.38410177
Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.
network
low complexity
asus
7.5
2021-02-01 CVE-2020-36109 Classic Buffer Overflow vulnerability in Asus Rt-Ax86U Firmware 3.0.0.4.386.46061/3.0.0.4.38649447
ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.
network
low complexity
asus CWE-120
critical
9.8
2021-01-18 CVE-2021-3166 Unrestricted Upload of File with Dangerous Type vulnerability in Asus Dsl-N14U B1 Firmware 1.1.2.3805
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices.
network
low complexity
asus CWE-434
7.5
2021-01-04 CVE-2020-35219 Improper Authentication vulnerability in Asus Dsl-N17U Firmware 1.1.0.2
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.
network
low complexity
asus CWE-287
critical
9.8
2020-12-09 CVE-2020-29656 Forced Browsing vulnerability in Asus Rt-Ac88U Firmware 3.0.0.4.386.46061
An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108.
network
low complexity
asus CWE-425
7.5