Vulnerabilities > Asus > WL 330Nul

DATE CVE VULNERABILITY TITLE RISK
2018-09-07 CVE-2018-0647 Cross-Site Request Forgery (CSRF) vulnerability in Asus Wl-330Nul Firmware 3.0.0.41
Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
asus CWE-352
6.8
2015-12-30 CVE-2015-7790 Cross-site Scripting vulnerability in Asus Wl-330Nul Firmware 3.0.0.41
Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
asus CWE-79
4.3
2015-12-30 CVE-2015-7789 Improper Input Validation vulnerability in Asus Wl-330Nul and Wl-33Nul Firmware
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.
low complexity
asus CWE-20
3.3
2015-12-30 CVE-2015-7788 Permissions, Privileges, and Access Controls vulnerability in Asus Wl-330Nul Firmware 3.0.0.41
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.
low complexity
asus CWE-264
5.8
2015-12-30 CVE-2015-7787 Information Exposure vulnerability in Asus Wl-330Nul Firmware 3.0.0.41
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase via unspecified vectors.
low complexity
asus CWE-200
3.3
2014-01-15 CVE-2013-7293 Improper Access Control vulnerability in Asus Wl-330Nul
The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname that does not always resolve to 192.168.1.1, which makes it easier for remote attackers to hijack the configuration traffic by controlling the server associated with that hostname.
network
low complexity
asus CWE-284
5.0