Vulnerability index

Browse CVEs

132 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rt Ax56u Firmware HIGH 8.8
CVE-2021-40556

A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the str…

No fix yet
Fix from $1,950 2022-10-06
Aura Ready Game Software Development Kit HIGH 7.8
CVE-2022-35899

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges …

No fix yet
Fix from $1,950 2022-07-21
Zenwifi Xd4s Firmware CRITICAL 9.0
CVE-2021-43702

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…

No fix yet
Fix from $2,300 2022-07-05
Dsl N14u B1 Firmware MEDIUM 5.4
CVE-2022-32988

Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc…

No fix yet
Fix from $1,600 2022-07-01
Control Center MEDIUM 6.5
CVE-2022-26668

ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform pa…

Mitigation only
Fix from $1,600 2022-06-20
Control Center MEDIUM 6.5
CVE-2022-26669

ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific A…

Mitigation only
Fix from $1,600 2022-06-20
Rt N53 Firmware CRITICAL 9.8
CVE-2022-31874EPSS 19%

ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

No fix yet
Fix from $2,300 2022-06-17
Dsl N14u B1 Firmware HIGH 7.5
CVE-2021-3254

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

No fix yet
Fix from $1,950 2022-05-11
Rt Ax56u Firmware HIGH 8.8
CVE-2022-23972

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker t…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.8
CVE-2022-23973

ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length.…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ac86u Firmware HIGH 8.8
CVE-2022-25596

ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter len…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ac86u Firmware HIGH 8.8
CVE-2022-25597

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to pe…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.1
CVE-2022-23970

ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.1
CVE-2022-23971

ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An…

No fix yet
Fix from $1,950 2022-04-07
Rt Ac86u Firmware MEDIUM 6.5
CVE-2022-25595

ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular req…

Mitigation only
Fix from $1,600 2022-04-07
Cmax6000 Firmware HIGH 7.5
CVE-2021-46247

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

No fix yet
Fix from $1,950 2022-02-17
Rt Ax56u Firmware MEDIUM 6.5
CVE-2022-22054

ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, whic…

Mitigation only
Fix from $1,600 2022-01-14
Rt Ac52u B1 Firmware MEDIUM 6.1
CVE-2021-46109

Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

No fix yet
Fix from $1,600 2022-01-03
Rt Ax56u Firmware HIGH 8.0
CVE-2021-44158

ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local…

Mitigation only
Fix from $1,950 2022-01-03
Rt N53 Firmware CRITICAL 9.8
CVE-2019-20082

ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

No fix yet
Fix from $2,300 2021-12-28
P453uj Bios MEDIUM 6.3
CVE-2021-41289

ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, loc…

Mitigation only
Fix from $1,600 2021-11-15
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28204

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obta…

Mitigation only
Fix from $1,950 2021-04-06
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28203

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator pe…

Mitigation only
Fix from $1,950 2021-04-06
Askey Rtf8115vw Firmware MEDIUM 6.1
CVE-2021-27403

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

No fix yet
Fix from $1,600 2021-02-19
Askey Rtf8115vw Firmware MEDIUM 6.1
CVE-2021-27404

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

No fix yet
Fix from $1,600 2021-02-19
Dsl N14u B1 Firmware HIGH 7.5
CVE-2021-3166

An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename…

No fix yet
Fix from $1,950 2021-01-18
Dsl N17u Firmware CRITICAL 9.8
CVE-2020-35219

The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication vi…

Mitigation only
Fix from $2,300 2021-01-04
Screenpad2 Upgrade Tool HIGH 7.8
CVE-2020-15009

AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX,…

Mitigation only
Fix from $1,950 2020-07-20
Asuswrt CRITICAL 9.8
CVE-2018-20334

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…

No fix yet
Fix from $2,300 2020-03-20
Asuswrt HIGH 7.5
CVE-2018-20333

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to t…

No fix yet
Fix from $1,950 2020-03-20