Vulnerabilities > Asus

DATE CVE VULNERABILITY TITLE RISK
2021-02-19 CVE-2021-27403 Cross-site Scripting vulnerability in Asus Askey Rtf8115Vw Firmware Brsvg11.11Rtftef001V6.54V014
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
network
asus CWE-79
4.3
2021-02-05 CVE-2021-3229 Unspecified vulnerability in Asus Rt-Ax3000 Firmware
Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.
network
low complexity
asus
7.8
2021-02-01 CVE-2020-36109 Classic Buffer Overflow vulnerability in Asus Rt-Ax86U Firmware
ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.
network
low complexity
asus CWE-120
7.5
2021-01-18 CVE-2021-3166 Unrestricted Upload of File with Dangerous Type vulnerability in Asus Dsl-N14U B1 Firmware 1.1.2.3805
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices.
network
low complexity
asus CWE-434
5.0
2021-01-04 CVE-2020-35219 Missing Authorization vulnerability in Asus Dsl-N17U Firmware 1.1.0.2
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.
network
low complexity
asus CWE-862
critical
10.0
2020-12-09 CVE-2020-29656 Information Exposure vulnerability in Asus Rt-Ac88U Firmware
An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108.
network
low complexity
asus CWE-200
5.0
2020-12-09 CVE-2020-29655 Injection vulnerability in Asus Rt-Ac88U Firmware
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108.
network
low complexity
asus CWE-74
5.0
2020-08-26 CVE-2020-15499 Cross-site Scripting vulnerability in Asus Rt-Ac1900P Firmware 3.0.0.4.385.10000/3.0.0.4.385.20252
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253.
network
asus CWE-79
4.3
2020-08-26 CVE-2020-15498 Improper Certificate Validation vulnerability in Asus Rt-Ac1900P Firmware 3.0.0.4.385.10000/3.0.0.4.385.20252
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253.
network
asus CWE-295
4.3
2020-07-20 CVE-2020-15009 Untrusted Search Path vulnerability in Asus Screenpad2 Upgrade Tool 1.0.3
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
local
asus CWE-426
4.4