Vulnerabilities > Asus > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-08-26 CVE-2020-15499 Cross-site Scripting vulnerability in Asus Rt-Ac1900P Firmware 3.0.0.4.385.10000/3.0.0.4.385.20252
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253.
network
asus CWE-79
4.3
2020-08-26 CVE-2020-15498 Improper Certificate Validation vulnerability in Asus Rt-Ac1900P Firmware 3.0.0.4.385.10000/3.0.0.4.385.20252
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253.
network
asus CWE-295
4.3
2020-07-20 CVE-2020-15009 Untrusted Search Path vulnerability in Asus Screenpad2 Upgrade Tool 1.0.3
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
local
asus CWE-426
4.4
2020-03-20 CVE-2018-20333 Information Exposure vulnerability in Asus Asuswrt 3.0.0.4.384.20308
An issue was discovered in ASUSWRT 3.0.0.4.384.20308.
network
low complexity
asus CWE-200
5.0
2020-02-27 CVE-2018-8878 Information Exposure vulnerability in multiple products
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
network
low complexity
asuswrt-merlin asus CWE-200
5.0
2020-02-27 CVE-2018-8877 Information Exposure vulnerability in multiple products
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
network
low complexity
asus asuswrt-merlin CWE-200
5.0
2020-01-28 CVE-2020-7997 Cross-site Scripting vulnerability in Asus Rt-Ac66U Firmware 3.0.0.4.37267
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
network
asus CWE-79
4.3
2019-12-20 CVE-2019-15912 Improper Input Validation vulnerability in Asus products
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.
network
low complexity
asus CWE-20
5.0
2019-12-20 CVE-2019-15910 Improper Input Validation vulnerability in Asus products
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.
network
low complexity
asus CWE-20
5.0
2019-12-18 CVE-2019-19235 Improper Input Validation vulnerability in Asus ATK Package
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution.
local
asus CWE-20
6.9