Vulnerabilities > Asus

DATE CVE VULNERABILITY TITLE RISK
2022-09-26 CVE-2021-41437 Injection vulnerability in Asus Rt-Ax88U Firmware
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
network
low complexity
asus CWE-74
6.5
2022-08-05 CVE-2022-26376 A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7..
network
low complexity
asus asuswrt-merlin
critical
9.8
2022-07-21 CVE-2022-35899 Unquoted Search Path or Element vulnerability in Asus Aura Ready Game Software Development KIT 1.0.0.4
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4.
local
low complexity
asus CWE-428
7.8
2022-07-05 CVE-2021-43702 Cross-site Scripting vulnerability in Asus products
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS).
network
low complexity
asus CWE-79
critical
9.0
2022-07-01 CVE-2022-32988 Cross-site Scripting vulnerability in Asus Dsl-N14U-B1 Firmware 1.1.2.3805
Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g.
network
low complexity
asus CWE-79
5.4
2022-06-20 CVE-2022-26668 Incorrect Authorization vulnerability in Asus Control Center 1.4.2.5
ASUS Control Center API has a broken access control vulnerability.
network
low complexity
asus CWE-863
6.5
2022-06-20 CVE-2022-26669 SQL Injection vulnerability in Asus Control Center 1.4.2.5
ASUS Control Center is vulnerable to SQL injection.
network
low complexity
asus CWE-89
6.5
2022-06-17 CVE-2022-31874 Command Injection vulnerability in Asus Rt-N53 Firmware 3.0.0.4.376.3754
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
network
low complexity
asus CWE-77
critical
9.8
2022-05-11 CVE-2021-3254 Unspecified vulnerability in Asus Dsl-N14U-B1 Firmware 1.1.2.3805
Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.
network
low complexity
asus
7.5
2022-04-22 CVE-2022-26672 Use of Hard-coded Credentials vulnerability in Asus Webstorage 3.10.1
ASUS WebStorage has a hardcoded API Token in the APP source code.
network
low complexity
asus CWE-798
critical
9.8