Vulnerability index

Browse CVEs

223 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rt Ac68u Firmware MEDIUM 6.1
CVE-2018-0582

Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers to inject arbitrary web script…

Fix: 3.0.0.4.380.1031+
Fix from $1,600 2018-05-14
Rt Ac51u Firmware CRITICAL 9.8
CVE-2018-8826

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N…

Mitigation only
Fix from $2,300 2018-04-20
Rt Ac66u Firmware CRITICAL 9.8
CVE-2018-9285

Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…

Fix: 3.0.0.4.382.39935 / 3.0.0.4.384.10007+
Fix from $2,300 2018-04-04
Rt N14uhp Firmware MEDIUM 6.1
CVE-2017-12590

ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.

Fix: 3.0.0.4.380.8015+
Fix from $1,600 2018-03-16
Asuswrt CRITICAL 9.6
CVE-2017-15655

Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.37…

Fix: 3.0.0.4.378+
Fix from $2,300 2018-01-31
Asuswrt HIGH 8.8
CVE-2017-15653

Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unau…

Fix: after 3.0.0.4.380.7743
Fix from $1,950 2018-01-31
Asuswrt HIGH 8.8
CVE-2017-15656

Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

Fix: after 3.0.0.4.380.7743
Fix from $1,950 2018-01-31
Asuswrt HIGH 8.3
CVE-2017-15654

Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative rout…

Fix: after 3.0.0.4.380.7743
Fix from $1,950 2018-01-31
Dsl Ac51 Firmware CRITICAL 9.8
CVE-2017-14698

ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N…

Patch available
Fix from $2,300 2018-01-29
Dsl Ac51 Firmware MEDIUM 6.5
CVE-2017-14699

Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U…

Patch available
Fix from $1,600 2018-01-29
Asuswrt CRITICAL 9.8
CVE-2018-5999EPSS 87%

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests cont…

Fix: 3.0.0.4.384_10007+
Fix from $2,300 2018-01-22
Asuswrt CRITICAL 9.8
CVE-2018-6000EPSS 85%

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functiona…

Fix: 3.0.0.4.384_10007+
Fix from $2,300 2018-01-22
Dsl N10s Firmware HIGH 8.8
CVE-2017-12592

ASUS DSL-N10S V2.1.16_APAC devices have a privilege escalation vulnerability. A normal user can escalate its privilege and perform administrative act…

No fix yet
Fix from $1,950 2017-08-18
Dsl N10s Firmware HIGH 8.8
CVE-2017-12593

ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.

No fix yet
Fix from $1,950 2017-08-18
Dsl N10s Firmware MEDIUM 5.4
CVE-2017-12591

ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.

No fix yet
Fix from $1,600 2017-08-18
Rt Ac1750 Firmware HIGH 8.8
CVE-2017-5891

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.

Patch available
Fix from $1,950 2017-05-10
Rt Ac1750 Firmware HIGH 7.5
CVE-2017-5892

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

Patch available
Fix from $1,950 2017-05-10
Rt Ac1750 Firmware MEDIUM 6.5
CVE-2017-8877

ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.

Mitigation only
Fix from $1,600 2017-05-10
Rt Ac1750 Firmware MEDIUM 6.5
CVE-2017-8878

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.

Mitigation only
Fix from $1,600 2017-05-10
Rt Ac66u Firmware CRITICAL 9.8
CVE-2013-4659EPSS 14%

Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on rout…

No fix yet
Fix from $2,300 2017-03-14
Rt Ac53 Firmware CRITICAL 9.8
CVE-2017-6548EPSS 21%

Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-A…

No fix yet
Fix from $2,300 2017-03-09
Rt Ac53 Firmware HIGH 8.8
CVE-2017-6549EPSS 8%

Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87…

No fix yet
Fix from $1,950 2017-03-09
Rt Ac53 Firmware MEDIUM 6.1
CVE-2017-6547

Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC…

No fix yet
Fix from $1,600 2017-03-09
Rt N56u Firmware MEDIUM 6.5
CVE-2017-5632

An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP a…

Mitigation only
Fix from $1,600 2017-01-30
Wl 330nul Firmware MEDIUM 6.1
CVE-2015-7790

Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote attackers to inject arbitrary we…

Fix: after 3.0.0.41
Fix from $1,600 2015-12-30
Wl 330nul Firmware HIGH 7.3
CVE-2015-7788

ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.

Fix: after 3.0.0.41
Fix from $1,950 2015-12-30
Tm 1900 HIGH 9.3
CVE-2015-6949EPSS 7%

Stack-based buffer overflow in the ASUS TM-AC1900 router allows remote attackers to execute arbitrary code via crafted HTTP header values.

Mitigation only
Fix from $1,950 2015-09-15
Rt G32 Firmware MEDIUM 6.8
CVE-2015-2676

Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the au…

No fix yet
Fix from $1,600 2015-03-23
Rt N66u Firmware MEDIUM 6.8
CVE-2014-7270

Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firm…

Fix: after 3.0.0.4.378.3754
Fix from $1,600 2015-02-01
Rt N66u Firmware MEDIUM 6.5
CVE-2014-7269

ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers…

Fix: after 3.0.0.4.378.3754
Fix from $1,600 2015-02-01