Show filters
336 Total Results
Displaying 11-20 of 336
Sort by:
Attacker Value
Unknown
CVE-2024-31163
Disclosure Date: June 14, 2024 (last updated January 05, 2025)
ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
0
Attacker Value
Unknown
CVE-2024-31162
Disclosure Date: June 14, 2024 (last updated January 05, 2025)
The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
0
Attacker Value
Unknown
CVE-2024-31161
Disclosure Date: June 14, 2024 (last updated August 17, 2024)
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
0
Attacker Value
Unknown
CVE-2024-31160
Disclosure Date: June 14, 2024 (last updated August 17, 2024)
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.
0
Attacker Value
Unknown
CVE-2024-31159
Disclosure Date: June 14, 2024 (last updated August 17, 2024)
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
0
Attacker Value
Unknown
CVE-2024-3080
Disclosure Date: June 14, 2024 (last updated January 05, 2025)
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
0
Attacker Value
Unknown
CVE-2024-3079
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
0
Attacker Value
Unknown
CVE-2024-0401
Disclosure Date: May 20, 2024 (last updated May 21, 2024)
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
0
Attacker Value
Unknown
CVE-2023-35720
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected ASUS RT-AX92U routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the mod_webdav.so module. When parsing a request, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-16078.
0
Attacker Value
Unknown
CVE-2024-1655
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.
0