Show filters
336 Total Results
Displaying 31-40 of 336
Sort by:
Attacker Value
Unknown

CVE-2023-39238

Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-39237

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-39236

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38033

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38032

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38031

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-4475

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Attacker Value
Unknown

CVE-2023-3699

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Attacker Value
Unknown

CVE-2023-3698

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Attacker Value
Unknown

CVE-2023-3697

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.