Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
asus vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-34359
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
Asus Rt-ax88u Firmware
7.8
CVSSv3
CVE-2023-26911
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
Asus Armoury Crate
Asus Setupasusservices
9.8
CVSSv3
CVE-2023-35087
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remot...
Asus Rt-ac86u Firmware 3.0.0.4 386 51529
Asus Rt-ax56u V2 Firmware 3.0.0.4.386 50460
7.2
CVSSv3
CVE-2023-35086
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrato...
Asus Rt-ac86u Firmware 3.0.0.4 386 51529
Asus Rt-ax56u V2 Firmware 3.0.0.4.386 50460
1 Github repository
5.3
CVSSv3
CVE-2023-31195
ASUS Router RT-AX3000 Firmware versions before 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencry...
Asus Rt-ax3000 Firmware
5.4
CVSSv3
CVE-2023-34941
A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyword List text field. NOTE: This vulnerability only aff...
Asus Rt-n10lx Firmware 2.0.0.39
7.5
CVSSv3
CVE-2023-34942
Asus RT-N10LX Router v2.0.0.39 exists to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Asus Rt-n10lx Firmware 2.0.0.39
7.5
CVSSv3
CVE-2023-34940
Asus RT-N10LX Router v2.0.0.39 exists to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Asus Rt-n10lx Firmware 2.0.0.39
8.8
CVSSv3
CVE-2023-28702
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
Asus Rt-ac86u Firmware 3.0.0.4.386.51255
7.2
CVSSv3
CVE-2023-28703
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrup...
Asus Rt-ac86u Firmware 3.0.0.4.386.51255
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »