Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown
CVE-2022-26376
Disclosure Date: July 27, 2022 (last updated October 08, 2023)
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-20334
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
0
Attacker Value
Unknown
CVE-2018-20335
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
0
Attacker Value
Unknown
CVE-2018-20333
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
0
Attacker Value
Unknown
CVE-2018-8877
Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
0
Attacker Value
Unknown
CVE-2018-8878
Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
0
Attacker Value
Unknown
CVE-2018-20336
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.
0
Attacker Value
Unknown
CVE-2017-15654
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.
0
Attacker Value
Unknown
CVE-2017-15655
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.
0
Attacker Value
Unknown
CVE-2017-15653
Disclosure Date: January 31, 2018 (last updated November 26, 2024)
Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.
0