Show filters
336 Total Results
Displaying 81-90 of 336
Sort by:
Attacker Value
Unknown

CVE-2022-26669

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.
Attacker Value
Unknown

CVE-2022-26668

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.
Attacker Value
Unknown

CVE-2022-26674

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown

CVE-2022-26673

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2022-26672

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.
Attacker Value
Unknown

CVE-2021-45757

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).
Attacker Value
Unknown

CVE-2021-45756

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
Attacker Value
Unknown

CVE-2022-22814

Disclosure Date: March 10, 2022 (last updated October 07, 2023)
The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
Attacker Value
Unknown

CVE-2022-25596

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
Attacker Value
Unknown

CVE-2022-25597

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.