Vulnerabilities > Asus
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-09-13 | CVE-2018-17022 | Out-of-bounds Write vulnerability in Asus Gt-Ac5300 Firmware Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c uses strcpy. | 7.2 |
2018-09-13 | CVE-2018-17021 | Cross-site Scripting vulnerability in Asus Gt-Ac5300 Firmware Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter. | 6.1 |
2018-09-13 | CVE-2018-17020 | Unspecified vulnerability in Asus Gt-Ac5300 Firmware ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line. | 7.5 |
2018-09-07 | CVE-2018-0647 | Cross-Site Request Forgery (CSRF) vulnerability in Asus Wl-330Nul Firmware 3.0.0.41 Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |
2018-08-27 | CVE-2018-15887 | OS Command Injection vulnerability in Asus Dsl-N12E C1 Firmware 1.1.2.3345 Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, such as shell metacharacters in the destIP parameter of a cmdMethod=ping request. | 8.8 |
2018-08-10 | CVE-2018-11492 | Unspecified vulnerability in Asus Hg100 Firmware ASUS HG100 devices allow denial of service via an IPv4 packet flood. | 7.5 |
2018-07-25 | CVE-2018-11491 | Improper Authentication vulnerability in Asus Hg100 Firmware 1.05.12 ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. | 9.8 |
2018-07-13 | CVE-2016-6558 | Command Injection vulnerability in Asus products A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. | 9.8 |
2018-07-13 | CVE-2016-6557 | Cross-Site Request Forgery (CSRF) vulnerability in Asus products In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. | 8.8 |
2018-05-14 | CVE-2018-0583 | Cross-site Scripting vulnerability in Asus Rt-Ac1200Hp Firmware Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |