Vulnerabilities > Asus > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-14 CVE-2018-18287 Information Exposure vulnerability in Asus Rt-Ac58U Firmware 3.0.0.4.380.6516
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page.
network
low complexity
asus CWE-200
5.3
2018-09-13 CVE-2018-17021 Cross-site Scripting vulnerability in Asus Gt-Ac5300 Firmware
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
network
low complexity
asus CWE-79
6.1
2018-05-14 CVE-2018-0583 Cross-site Scripting vulnerability in Asus Rt-Ac1200Hp Firmware
Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
asus CWE-79
6.1
2018-05-14 CVE-2018-0582 Cross-site Scripting vulnerability in Asus Rt-Ac68U Firmware
Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
asus CWE-79
6.1
2018-05-14 CVE-2018-0581 Cross-site Scripting vulnerability in Asus Rt-Ac87U Firmware 3.0.0.4.378.3754
Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
asus CWE-79
6.1
2018-03-16 CVE-2017-12590 Cross-site Scripting vulnerability in Asus Rt-N14Uhp Firmware
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
network
low complexity
asus CWE-79
6.1
2018-01-29 CVE-2017-14699 XXE vulnerability in Asus products
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.
network
low complexity
asus CWE-611
6.5
2017-08-18 CVE-2017-12591 Cross-site Scripting vulnerability in Asus Dsl-N10S Firmware V2.1.16Apac
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.
network
low complexity
asus CWE-79
5.4
2017-05-10 CVE-2017-8878 Information Exposure vulnerability in Asus Rt-Ac1750 Firmware 3.0.0.4.380.7266
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.
network
low complexity
asus CWE-200
6.5
2017-05-10 CVE-2017-8877 Information Exposure vulnerability in Asus Rt-Ac1750 Firmware 3.0.0.4.380.7266
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.
network
low complexity
asus CWE-200
6.5