VYPR

HG100

by Asus

CVEs (7)

  • CVE-2019-11061CriAug 29, 2019
    risk 0.65cvss 10.0epss 0.04

    A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10…

  • CVE-2019-15911CriDec 20, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart…

  • CVE-2018-11491CriJul 25, 2018
    risk 0.64cvss 9.8epss 0.07

    ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.

  • CVE-2018-11492HigAug 10, 2018
    risk 0.53cvss 7.5epss 0.11

    ASUS HG100 devices allow denial of service via an IPv4 packet flood.

  • CVE-2019-15912HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15910HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2019-11060HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.03

    The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a…