Vulnerability index

Browse CVEs

223 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control Center MEDIUM 6.5
CVE-2022-26669

ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific A…

Mitigation only
Fix from $1,600 2022-06-20
Rt N53 Firmware CRITICAL 9.8
CVE-2022-31874EPSS 19%

ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

No fix yet
Fix from $2,300 2022-06-17
Dsl N14u B1 Firmware HIGH 7.5
CVE-2021-3254

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

No fix yet
Fix from $1,950 2022-05-11
Webstorage CRITICAL 9.8
CVE-2022-26672

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with…

Fix: 3.10.2+
Fix from $2,300 2022-04-22
Rt Ax88u Firmware CRITICAL 9.8
CVE-2022-26674

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform rem…

Fix: 3.0.0.4.386.46065+
Fix from $2,300 2022-04-22
Rt Ax88u Firmware MEDIUM 5.4
CVE-2022-26673

ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can explo…

Fix: 3.0.0.4.386.46065+
Fix from $1,600 2022-04-22
Rt Ax56u Firmware HIGH 8.8
CVE-2022-23972

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker t…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.8
CVE-2022-23973

ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length.…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ac86u Firmware HIGH 8.8
CVE-2022-25596

ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter len…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ac86u Firmware HIGH 8.8
CVE-2022-25597

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to pe…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.1
CVE-2022-23970

ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An…

Mitigation only
Fix from $1,950 2022-04-07
Rt Ax56u Firmware HIGH 8.1
CVE-2022-23971

ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An…

No fix yet
Fix from $1,950 2022-04-07
Rt Ac86u Firmware MEDIUM 6.5
CVE-2022-25595

ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular req…

Mitigation only
Fix from $1,600 2022-04-07
Rt Ac68u Firmware CRITICAL 9.8
CVE-2021-45756

Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

Fix: 3.0.0.4.384.82072 / 3.0.0.4.385.20633+
Fix from $2,300 2022-03-23
Rt Ac68u Firmware HIGH 7.5
CVE-2021-45757

ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).

Fix: after 3.0.0.4.385.20852
Fix from $1,950 2022-03-23
Myasus CRITICAL 9.8
CVE-2022-22814

The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

Fix: 3.1.2.0+
Fix from $2,300 2022-03-10
Rog Live Service HIGH 7.7
CVE-2022-22262

ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since t…

Fix: 1.3.3.0+
Fix from $1,950 2022-03-01
Cmax6000 Firmware HIGH 7.5
CVE-2021-46247

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

No fix yet
Fix from $1,950 2022-02-17
Vc65 C1 Firmware HIGH 7.8
CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interru…

Fix: 601 / 902+
Fix from $1,950 2022-01-21
Rt Ax56u Firmware MEDIUM 6.5
CVE-2022-22054

ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, whic…

Mitigation only
Fix from $1,600 2022-01-14
Rt Ac52u B1 Firmware MEDIUM 6.1
CVE-2021-46109

Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

No fix yet
Fix from $1,600 2022-01-03
Rt Ax56u Firmware HIGH 8.0
CVE-2021-44158

ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local…

Mitigation only
Fix from $1,950 2022-01-03
Rt N53 Firmware CRITICAL 9.8
CVE-2019-20082

ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

No fix yet
Fix from $2,300 2021-12-28
Gt Ax11000 Firmware CRITICAL 9.8
CVE-2021-41435EPSS 6%

A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, …

Fix: 3.0.0.4.386.45898+
Fix from $2,300 2021-11-19
Gt Ax11000 Firmware HIGH 7.5
CVE-2021-41436

An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U …

Fix: 3.0.0.4.386.45898+
Fix from $1,950 2021-11-19
P453uj Bios MEDIUM 6.3
CVE-2021-41289

ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, loc…

Mitigation only
Fix from $1,600 2021-11-15
Gt Axe11000 Firmware MEDIUM 5.3
CVE-2021-37910

ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated atta…

Fix: 3.0.0.4.386.45898+
Fix from $1,600 2021-11-12
Ux582lr Firmware MEDIUM 6.8
CVE-2021-42055

ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.

Fix: 303+
Fix from $1,600 2021-10-18
Armoury Crate Lite Service HIGH 7.3
CVE-2021-40981

ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%…

Fix: 4.2.10+
Fix from $1,950 2021-09-27
Lyra Mini Firmware CRITICAL 9.8
CVE-2021-32030 KEVEPSS 99%

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass …

Fix: 3.0.0.4.384.46630 / 3.0.0.4.386.42643+
Fix from $2,300 2021-05-06