Vulnerabilities > Asus > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-10-14 | CVE-2018-18287 | Information Exposure vulnerability in Asus Rt-Ac58U Firmware 3.0.0.4.380.6516 On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page. | 5.3 |
2018-09-13 | CVE-2018-17021 | Cross-site Scripting vulnerability in Asus Gt-Ac5300 Firmware Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter. | 6.1 |
2018-05-14 | CVE-2018-0583 | Cross-site Scripting vulnerability in Asus Rt-Ac1200Hp Firmware Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2018-05-14 | CVE-2018-0582 | Cross-site Scripting vulnerability in Asus Rt-Ac68U Firmware Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2018-05-14 | CVE-2018-0581 | Cross-site Scripting vulnerability in Asus Rt-Ac87U Firmware 3.0.0.4.378.3754 Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2018-03-16 | CVE-2017-12590 | Cross-site Scripting vulnerability in Asus Rt-N14Uhp Firmware ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter. | 6.1 |
2018-01-29 | CVE-2017-14699 | XXE vulnerability in Asus products Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request. | 6.5 |
2017-08-18 | CVE-2017-12591 | Cross-site Scripting vulnerability in Asus Dsl-N10S Firmware V2.1.16Apac ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter. | 5.4 |
2017-05-10 | CVE-2017-8878 | Information Exposure vulnerability in Asus Rt-Ac1750 Firmware 3.0.0.4.380.7266 ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml. | 6.5 |
2017-05-10 | CVE-2017-8877 | Information Exposure vulnerability in Asus Rt-Ac1750 Firmware 3.0.0.4.380.7266 ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID. | 6.5 |