Show filters
336 Total Results
Displaying 161-170 of 336
Sort by:
Attacker Value
Unknown

CVE-2020-10649

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
Attacker Value
Unknown

CVE-2018-20334

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Attacker Value
Unknown

CVE-2018-20335

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
Attacker Value
Unknown

CVE-2018-20333

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Attacker Value
Unknown

CVE-2019-11688

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.
Attacker Value
Unknown

CVE-2019-11689

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.
Attacker Value
Unknown

CVE-2018-8877

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
Attacker Value
Unknown

CVE-2018-8878

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
Attacker Value
Unknown

CVE-2013-3093

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
ASUS RT-N56U devices allow CSRF.
Attacker Value
Unknown

CVE-2020-7997

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.