Skip to main content

Vendor/product archive

asus / asuswrt CVEs

Beta · best-effort

10 CVEs tagged to asus / asuswrt5 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2017-15656

Published Jan 31, 2018

Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15655

Published Jan 31, 2018

Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15654

Published Jan 31, 2018

Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15653

Published Jan 31, 2018

Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6000

Published Jan 22, 2018

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5999

Published Jan 22, 2018

An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1