Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-3080

Disclosure Date: June 14, 2024 (last updated January 05, 2025)
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
0
Attacker Value
Unknown

CVE-2024-3079

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
0
Attacker Value
Unknown

CVE-2024-0401

Disclosure Date: May 20, 2024 (last updated May 21, 2024)
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
0
Attacker Value
Unknown

CVE-2023-41349

Disclosure Date: September 18, 2023 (last updated October 08, 2023)
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.
Attacker Value
Unknown

CVE-2023-34360

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.
Attacker Value
Unknown

CVE-2023-34359

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
Attacker Value
Unknown

CVE-2023-34358

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
Attacker Value
Unknown

CVE-2021-41437

Disclosure Date: September 26, 2022 (last updated October 08, 2023)
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
Attacker Value
Unknown

CVE-2021-43702

Disclosure Date: July 05, 2022 (last updated October 07, 2023)
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
Attacker Value
Unknown

CVE-2022-26674

Disclosure Date: April 22, 2022 (last updated November 29, 2024)
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0