Show filters
336 Total Results
Displaying 21-30 of 336
Sort by:
Attacker Value
Unknown

CVE-2023-5716

Disclosure Date: January 19, 2024 (last updated January 30, 2024)
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.
Attacker Value
Unknown

CVE-2023-47678

Disclosure Date: November 15, 2023 (last updated November 22, 2023)
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
Attacker Value
Unknown

CVE-2023-41348

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
Attacker Value
Unknown

CVE-2023-41347

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
Attacker Value
Unknown

CVE-2023-41346

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
Attacker Value
Unknown

CVE-2023-41345

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.
Attacker Value
Unknown

CVE-2023-41349

Disclosure Date: September 18, 2023 (last updated October 08, 2023)
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.
Attacker Value
Unknown

CVE-2023-39780

Disclosure Date: September 11, 2023 (last updated October 08, 2023)
ASUS RT-AX55 v3.0.0.4.386.51598 was discovered to contain an authenticated command injection vulnerability.
Attacker Value
Unknown

CVE-2023-39240

Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-39239

Disclosure Date: September 07, 2023 (last updated March 27, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.