Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-26376

Disclosure Date: July 27, 2022 (last updated October 08, 2023)
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-20334

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Attacker Value
Unknown

CVE-2018-20335

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
Attacker Value
Unknown

CVE-2018-20333

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Attacker Value
Unknown

CVE-2018-8877

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
Attacker Value
Unknown

CVE-2018-8878

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
Attacker Value
Unknown

CVE-2018-20336

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.
Attacker Value
Unknown

CVE-2017-15654

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.
0
Attacker Value
Unknown

CVE-2017-15655

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.
0
Attacker Value
Unknown

CVE-2017-15653

Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.
0