Vulnerability index

Browse CVEs

223 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-35087 It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific valu… Rt Ac86u Firmware Mitigation only Fix from $2,3002023-07-21 HIGH 7.2 CVE-2023-35086EPSS 39% It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format strin… Rt Ac86u Firmware Mitigation only Fix from $1,9502023-07-21 MEDIUM 5.3 CVE-2023-31195 ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a positi… Rt Ax3000 Firmware 3.0.0.4.388.23403+ Fix from $1,6002023-06-13 HIGH 7.5 CVE-2023-34940 Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only a… Rt N10lx Firmware No fix yet Fix from $1,9502023-06-12 HIGH 7.5 CVE-2023-34942 Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only a… Rt N10lx Firmware No fix yet Fix from $1,9502023-06-12 MEDIUM 5.4 CVE-2023-34941EPSS 24% A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitra… Rt N10lx Firmware No fix yet Fix from $1,6002023-06-12 HIGH 8.8 CVE-2023-28702 ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this … Rt Ac86u Firmware Mitigation only Fix from $1,9502023-06-02 HIGH 7.2 CVE-2023-28703 ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length… Rt Ac86u Firmware Mitigation only Fix from $1,9502023-06-02 MEDIUM 5.2 CVE-2023-29772EPSS 11% A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware v… Rt Ac51u Firmware after 3.0.0.4.380.8591 Fix from $1,6002023-05-02 CRITICAL 9.8 CVE-2023-26602EPSS 17% ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snm… Asmb8 Ikvm Firmware after 1.14.51 Fix from $2,3002023-02-26 HIGH 7.8 CVE-2022-42455 ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS so… Armoury Crate 5.3.4.1+ Fix from $1,9502023-02-15 CRITICAL 9.1 CVE-2021-37315 Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to w… Rt Ac68u Firmware 3.0.0.4.386.41634+ Fix from $2,3002023-02-03 CRITICAL 9.1 CVE-2021-37317 Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write ar… Rt Ac68u Firmware 3.0.0.4.386.41634+ Fix from $2,3002023-02-03 HIGH 7.5 CVE-2021-37316 SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive… Rt Ac68u Firmware 3.0.0.4.386.41634+ Fix from $1,9502023-02-03 HIGH 8.1 CVE-2022-35401EPSS 21% An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-craft… Rt Ax82u Firmware No fix yet Fix from $1,9502023-01-10 HIGH 7.5 CVE-2022-38105 An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration serv… Rt Ax82u Firmware No fix yet Fix from $1,9502023-01-10 HIGH 7.5 CVE-2022-38393EPSS 19% A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's conf… Rt Ax82u Firmware No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2022-44898 The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102… Aura Sync after 1.07.79 Fix from $1,9502022-12-14 CRITICAL 9.8 CVE-2022-4221 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated at… Nas M25 Firmware after 1.0.1.7 Fix from $2,3002022-12-01 HIGH 7.5 CVE-2020-23648 Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the admi… Rt N12e Firmware No fix yet Fix from $1,9502022-10-19 HIGH 7.8 CVE-2022-36438 AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used … Asusswitch 1.0.10.0 / 3.1.5.0+ Fix from $1,9502022-10-18 MEDIUM 6.0 CVE-2022-36439 AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp dire… Asusliveupdate 1.0.45.0 / 1.0.53.0+ Fix from $1,6002022-10-18 HIGH 8.8 CVE-2021-40556 A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the str… Rt Ax56u Firmware No fix yet Fix from $1,9502022-10-06 MEDIUM 5.9 CVE-2022-38699 Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general us… Armoury Crate Service 5.2.10.0+ Fix from $1,6002022-09-28 MEDIUM 6.5 CVE-2021-41437 An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an… Rt Ax88u Firmware 3.0.0.4.388.20558+ Fix from $1,6002022-09-26 CRITICAL 9.8 CVE-2022-26376 A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t… Asuswrt 3.0.0.4.386_48706 / 3.0.0.4.386_48750+ Fix from $2,3002022-08-05 HIGH 7.8 CVE-2022-35899 There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges … Aura Ready Game Software Development Kit No fix yet Fix from $1,9502022-07-21 CRITICAL 9.0 CVE-2021-43702 ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if… Zenwifi Xd4s Firmware No fix yet Fix from $2,3002022-07-05 MEDIUM 5.4 CVE-2022-32988 Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc… Dsl N14u B1 Firmware No fix yet Fix from $1,6002022-07-01 MEDIUM 6.5 CVE-2022-26668 ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform pa… Control Center Mitigation only Fix from $1,6002022-06-20