Show filters
336 Total Results
Displaying 61-70 of 336
Sort by:
Attacker Value
Unknown
CVE-2021-37316
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
0
Attacker Value
Unknown
CVE-2021-37315
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
0
Attacker Value
Unknown
CVE-2022-38393
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-38105
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packets can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-35401
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2022-44898
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
0
Attacker Value
Unknown
CVE-2022-4221
Disclosure Date: December 01, 2022 (last updated November 08, 2023)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
0
Attacker Value
Unknown
CVE-2020-23648
Disclosure Date: October 19, 2022 (last updated October 08, 2023)
Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.
0
Attacker Value
Unknown
CVE-2022-36439
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.
0
Attacker Value
Unknown
CVE-2022-36438
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0.
0