Show filters
336 Total Results
Displaying 151-160 of 336
Sort by:
Attacker Value
Unknown
CVE-2021-3229
Disclosure Date: February 05, 2021 (last updated November 28, 2024)
Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.
0
Attacker Value
Unknown
CVE-2020-36109
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.
0
Attacker Value
Unknown
CVE-2021-3166
Disclosure Date: January 18, 2021 (last updated February 22, 2025)
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, resulting in a persistent outage of those services.
0
Attacker Value
Unknown
CVE-2020-35219
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.
0
Attacker Value
Unknown
CVE-2020-29655
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker might be able to influence the appearance of the login page, aka text injection.
0
Attacker Value
Unknown
CVE-2020-29656
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=General&special_cgi=get_language makes it possible to reach "unknown functionality" in a "known to be easy" manner via an unspecified "public exploit."
0
Attacker Value
Unknown
CVE-2020-15498
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.
0
Attacker Value
Unknown
CVE-2020-15499
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.
0
Attacker Value
Unknown
CVE-2020-15009
Disclosure Date: July 20, 2020 (last updated February 21, 2025)
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
0
Attacker Value
Unknown
CVE-2019-17603
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
0