Vulnerability index

Browse CVEs

223 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zenwifi Ax \(xt8\) Firmware HIGH 7.5
CVE-2021-3128

In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a …

Fix: 3.0.0.4.386.42095 / 9.0.0.4.386.41994+
Fix from $1,950 2021-04-12
Gputweak Ii HIGH 7.8
CVE-2021-28685

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one…

Fix: 2.3.0.3+
Fix from $1,950 2021-04-08
Gputweak Ii MEDIUM 5.5
CVE-2021-28686

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enab…

Fix: 2.3.0.3+
Fix from $1,600 2021-04-08
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28204

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obta…

Mitigation only
Fix from $1,950 2021-04-06
Z10pr D16 Firmware HIGH 7.2
CVE-2021-28203

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator pe…

Mitigation only
Fix from $1,950 2021-04-06
Ux360ca Bios HIGH 8.2
CVE-2021-26943

The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory locations, i…

Fix: 304+
Fix from $1,950 2021-03-31
Askey Rtf8115vw Firmware MEDIUM 6.1
CVE-2021-27403

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

No fix yet
Fix from $1,600 2021-02-19
Askey Rtf8115vw Firmware MEDIUM 6.1
CVE-2021-27404

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

No fix yet
Fix from $1,600 2021-02-19
Rt Ax3000 Firmware HIGH 7.5
CVE-2021-3229

Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device …

Fix: after 3.0.0.4.384_10177
Fix from $1,950 2021-02-05
Rt Ax86u Firmware CRITICAL 9.8
CVE-2020-36109

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can…

Fix: 9.0.0.4_386+
Fix from $2,300 2021-02-01
Dsl N14u B1 Firmware HIGH 7.5
CVE-2021-3166

An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename…

No fix yet
Fix from $1,950 2021-01-18
Dsl N17u Firmware CRITICAL 9.8
CVE-2020-35219

The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication vi…

Mitigation only
Fix from $2,300 2021-01-04
Rt Ac88u Firmware HIGH 7.5
CVE-2020-29656

An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_m…

Fix: 3.1.0.108+
Fix from $1,950 2020-12-09
Rt Ac88u Firmware HIGH 7.5
CVE-2020-29655

An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaste…

Fix: 3.1.0.108+
Fix from $1,950 2020-12-09
Rt Ac1900p Firmware MEDIUM 6.1
CVE-2020-15499

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.

Fix: 3.0.0.4.385.20253+
Fix from $1,600 2020-08-26
Rt Ac1900p Firmware MEDIUM 5.9
CVE-2020-15498

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update…

Fix: 3.0.0.4.385.20253+
Fix from $1,600 2020-08-26
Screenpad2 Upgrade Tool HIGH 7.8
CVE-2020-15009

AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX,…

Mitigation only
Fix from $1,950 2020-07-20
Aura Sync HIGH 7.8
CVE-2019-17603

Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users …

Fix: after 1.07.71
Fix from $1,950 2020-06-02
Device Activation HIGH 7.8
CVE-2020-10649

DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional rest…

Fix: 1.0.7.0+
Fix from $1,950 2020-03-25
Asuswrt CRITICAL 9.8
CVE-2018-20334

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell me…

No fix yet
Fix from $2,300 2020-03-20
Asuswrt HIGH 7.5
CVE-2018-20333

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to t…

No fix yet
Fix from $1,950 2020-03-20
Asuswrt HIGH 7.5
CVE-2018-20335

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= …

No fix yet
Fix from $1,950 2020-03-20
Asus Firmware MEDIUM 5.3
CVE-2018-8877

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem…

Fix: 3.0.0.4.382.50470 / 384.4+
Fix from $1,600 2020-02-27
Rt N56u Firmware HIGH 8.8
CVE-2013-3093

ASUS RT-N56U devices allow CSRF.

Mitigation only
Fix from $1,950 2020-01-28
Rt Ac66u Firmware MEDIUM 6.1
CVE-2020-7997

ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.

No fix yet
Fix from $1,600 2020-01-28
Hg100 Firmware CRITICAL 9.8
CVE-2019-15911

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in Z…

No fix yet
Fix from $2,300 2019-12-20
Hg100 Firmware HIGH 7.5
CVE-2019-15910

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover Zi…

No fix yet
Fix from $1,950 2019-12-20
Hg100 Firmware HIGH 7.5
CVE-2019-15912

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust cen…

No fix yet
Fix from $1,950 2019-12-20
Atk Package HIGH 7.0
CVE-2019-19235

AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. T…

Fix: 1.0.0061+
Fix from $1,950 2019-12-18
Rt Ac66u Firmware CRITICAL 9.8
CVE-2018-8879EPSS 17%

Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allow…

Fix: 3.0.0.4.382.50470+
Fix from $2,300 2019-11-21