Vulnerability index

Browse CVEs

223 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rt Ac86u Firmware CRITICAL 9.8
CVE-2023-35087

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific valu…

Mitigation only
Fix from $2,300 2023-07-21
Rt Ac86u Firmware HIGH 7.2
CVE-2023-35086EPSS 39%

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format strin…

Mitigation only
Fix from $1,950 2023-07-21
Rt Ax3000 Firmware MEDIUM 5.3
CVE-2023-31195

ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a positi…

Fix: 3.0.0.4.388.23403+
Fix from $1,600 2023-06-13
Rt N10lx Firmware HIGH 7.5
CVE-2023-34940

Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only a…

No fix yet
Fix from $1,950 2023-06-12
Rt N10lx Firmware HIGH 7.5
CVE-2023-34942

Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only a…

No fix yet
Fix from $1,950 2023-06-12
Rt N10lx Firmware MEDIUM 5.4
CVE-2023-34941EPSS 24%

A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitra…

No fix yet
Fix from $1,600 2023-06-12
Rt Ac86u Firmware HIGH 8.8
CVE-2023-28702

ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this …

Mitigation only
Fix from $1,950 2023-06-02
Rt Ac86u Firmware HIGH 7.2
CVE-2023-28703

ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length…

Mitigation only
Fix from $1,950 2023-06-02
Rt Ac51u Firmware MEDIUM 5.2
CVE-2023-29772EPSS 11%

A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware v…

Fix: after 3.0.0.4.380.8591
Fix from $1,600 2023-05-02
Asmb8 Ikvm Firmware CRITICAL 9.8
CVE-2023-26602EPSS 17%

ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snm…

Fix: after 1.14.51
Fix from $2,300 2023-02-26
Armoury Crate HIGH 7.8
CVE-2022-42455

ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS so…

Fix: 5.3.4.1+
Fix from $1,950 2023-02-15
Rt Ac68u Firmware CRITICAL 9.1
CVE-2021-37315

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to w…

Fix: 3.0.0.4.386.41634+
Fix from $2,300 2023-02-03
Rt Ac68u Firmware CRITICAL 9.1
CVE-2021-37317

Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write ar…

Fix: 3.0.0.4.386.41634+
Fix from $2,300 2023-02-03
Rt Ac68u Firmware HIGH 7.5
CVE-2021-37316

SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive…

Fix: 3.0.0.4.386.41634+
Fix from $1,950 2023-02-03
Rt Ax82u Firmware HIGH 8.1
CVE-2022-35401EPSS 21%

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-craft…

No fix yet
Fix from $1,950 2023-01-10
Rt Ax82u Firmware HIGH 7.5
CVE-2022-38105

An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration serv…

No fix yet
Fix from $1,950 2023-01-10
Rt Ax82u Firmware HIGH 7.5
CVE-2022-38393EPSS 19%

A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's conf…

No fix yet
Fix from $1,950 2023-01-10
Aura Sync HIGH 7.8
CVE-2022-44898

The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102…

Fix: after 1.07.79
Fix from $1,950 2022-12-14
Nas M25 Firmware CRITICAL 9.8
CVE-2022-4221

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated at…

Fix: after 1.0.1.7
Fix from $2,300 2022-12-01
Rt N12e Firmware HIGH 7.5
CVE-2020-23648

Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the admi…

No fix yet
Fix from $1,950 2022-10-19
Asusswitch HIGH 7.8
CVE-2022-36438

AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used …

Fix: 1.0.10.0 / 3.1.5.0+
Fix from $1,950 2022-10-18
Asusliveupdate MEDIUM 6.0
CVE-2022-36439

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp dire…

Fix: 1.0.45.0 / 1.0.53.0+
Fix from $1,600 2022-10-18
Rt Ax56u Firmware HIGH 8.8
CVE-2021-40556

A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the str…

No fix yet
Fix from $1,950 2022-10-06
Armoury Crate Service MEDIUM 5.9
CVE-2022-38699

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general us…

Fix: 5.2.10.0+
Fix from $1,600 2022-09-28
Rt Ax88u Firmware MEDIUM 6.5
CVE-2021-41437

An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an…

Fix: 3.0.0.4.388.20558+
Fix from $1,600 2022-09-26
Asuswrt CRITICAL 9.8
CVE-2022-26376

A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…

Fix: 3.0.0.4.386_48706 / 3.0.0.4.386_48750+
Fix from $2,300 2022-08-05
Aura Ready Game Software Development Kit HIGH 7.8
CVE-2022-35899

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges …

No fix yet
Fix from $1,950 2022-07-21
Zenwifi Xd4s Firmware CRITICAL 9.0
CVE-2021-43702

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…

No fix yet
Fix from $2,300 2022-07-05
Dsl N14u B1 Firmware MEDIUM 5.4
CVE-2022-32988

Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc…

No fix yet
Fix from $1,600 2022-07-01
Control Center MEDIUM 6.5
CVE-2022-26668

ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform pa…

Mitigation only
Fix from $1,600 2022-06-20