VYPR

Asuswrt

by Asus

CVEs (8)

  • CVE-2018-6000CriJan 22, 2018
    risk 0.73cvss 9.8epss 0.85

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable…

  • CVE-2018-20334CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

  • CVE-2017-15655CriJan 31, 2018
    risk 0.63cvss 9.6epss 0.03

    Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are…

  • CVE-2017-15656HigJan 31, 2018
    risk 0.57cvss 8.8epss 0.01

    Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

  • CVE-2017-15653HigJan 31, 2018
    risk 0.57cvss 8.8epss 0.02

    Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.

  • CVE-2017-15654HigJan 31, 2018
    risk 0.54cvss 8.3epss 0.02

    Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

  • CVE-2021-3229HigFeb 5, 2021
    risk 0.49cvss 7.5epss 0.03

    Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.

  • CVE-2018-20336HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.