4
CVSSv2

CVE-2017-14699

Published: 29/01/2018 Updated: 22/02/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.

Vulnerable Product Search on Vulmon Subscribe to Product

asus dsl-ac51_firmware -

asus dsl-ac52u_firmware -

asus dsl-ac55u_firmware -

asus dsl-n55u_c1_firmware -

asus dsl-n55u_d1_firmware -

asus dsl-ac56u_firmware -

asus dsl-n10_c1_firmware -

asus dsl-n12u_c1_firmware -

asus dsl-n12e_c1_firmware -

asus dsl-n14u_firmware -

asus dsl-n14u-b1_firmware -

asus dsl-n16_firmware -

asus dsl-n16u_firmware -

asus dsl-n17u_firmware -

asus dsl-n66u_firmware -

asus dsl-ac750_firmware -