Vulnerabilities > Asus

DATE CVE VULNERABILITY TITLE RISK
2018-09-13 CVE-2018-17022 Out-of-bounds Write vulnerability in Asus Gt-Ac5300 Firmware
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c uses strcpy.
network
low complexity
asus CWE-787
7.2
2018-09-13 CVE-2018-17021 Cross-site Scripting vulnerability in Asus Gt-Ac5300 Firmware
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
network
low complexity
asus CWE-79
6.1
2018-09-13 CVE-2018-17020 Unspecified vulnerability in Asus Gt-Ac5300 Firmware
ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line.
network
low complexity
asus
7.5
2018-09-07 CVE-2018-0647 Cross-Site Request Forgery (CSRF) vulnerability in Asus Wl-330Nul Firmware 3.0.0.41
Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
asus CWE-352
8.8
2018-08-27 CVE-2018-15887 OS Command Injection vulnerability in Asus Dsl-N12E C1 Firmware 1.1.2.3345
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, such as shell metacharacters in the destIP parameter of a cmdMethod=ping request.
network
low complexity
asus CWE-78
8.8
2018-08-10 CVE-2018-11492 Unspecified vulnerability in Asus Hg100 Firmware
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
network
low complexity
asus
7.5
2018-07-25 CVE-2018-11491 Improper Authentication vulnerability in Asus Hg100 Firmware 1.05.12
ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.
network
low complexity
asus CWE-287
critical
9.8
2018-07-13 CVE-2016-6558 Command Injection vulnerability in Asus products
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter.
network
low complexity
asus CWE-77
critical
9.8
2018-07-13 CVE-2016-6557 Cross-Site Request Forgery (CSRF) vulnerability in Asus products
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user.
network
low complexity
asus CWE-352
8.8
2018-05-14 CVE-2018-0583 Cross-site Scripting vulnerability in Asus Rt-Ac1200Hp Firmware
Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
asus CWE-79
6.1