Vulnerabilities > Asus > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-41345 OS Command Injection vulnerability in Asus Rt-Ax55 Firmware 3.0.0.4.386.51598
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module.
network
low complexity
asus CWE-78
8.8
2023-11-03 CVE-2023-41346 OS Command Injection vulnerability in Asus Rt-Ax55 Firmware 3.0.0.4.386.51598
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module.
network
low complexity
asus CWE-78
8.8
2023-11-03 CVE-2023-41347 OS Command Injection vulnerability in Asus Rt-Ax55 Firmware 3.0.0.4.386.51598
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module.
network
low complexity
asus CWE-78
8.8
2023-11-03 CVE-2023-41348 OS Command Injection vulnerability in Asus Rt-Ax55 Firmware 3.0.0.4.386.51598
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module.
network
low complexity
asus CWE-78
8.8
2023-09-11 CVE-2023-39780 Command Injection vulnerability in Asus Rt-Ax55 Firmware 3.0.0.4.386.51598
ASUS RT-AX55 v3.0.0.4.386.51598 was discovered to contain an authenticated command injection vulnerability.
network
low complexity
asus CWE-77
8.8
2023-09-07 CVE-2023-38031 Unspecified vulnerability in Asus Rt-Ac86U Firmware 3.0.0.438651529
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character.
network
low complexity
asus
8.8
2023-08-08 CVE-2023-39086 Cleartext Transmission of Sensitive Information vulnerability in Asus Rt-Ac66U B1 Firmware 3.0.0.4.28651665
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
network
low complexity
asus CWE-319
7.5
2023-07-26 CVE-2023-26911 Unquoted Search Path or Element vulnerability in Asus Armoury Crate and Setupasusservices
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
local
low complexity
asus CWE-428
7.8
2023-06-12 CVE-2023-34940 Out-of-bounds Write vulnerability in Asus Rt-N10Lx Firmware 2.0.0.39
Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html.
network
low complexity
asus CWE-787
7.5
2023-06-12 CVE-2023-34942 Out-of-bounds Write vulnerability in Asus Rt-N10Lx Firmware 2.0.0.39
Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html.
network
low complexity
asus CWE-787
7.5