VYPR

Vendor CVEs

Asus

All CVEs

285 total · sorted by risk
  • CVE-2023-34940Jun 12, 2023
    risk 0.00cvss epss 0.01

    Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-34941Jun 12, 2023
    risk 0.00cvss epss 0.24

    A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyword List text field. NOTE: This vulnerability only affects…

  • CVE-2023-34942Jun 12, 2023
    risk 0.00cvss epss 0.01

    Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-28702Jun 2, 2023
    risk 0.00cvss epss 0.01

    ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.

  • CVE-2023-28703Jun 2, 2023
    risk 0.00cvss epss 0.01

    ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt…

  • CVE-2023-29772May 2, 2023
    risk 0.00cvss epss 0.11

    A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or HTML via a malicious network…

  • CVE-2022-42455Feb 15, 2023
    risk 0.00cvss epss 0.00

    ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw read and write access to port I/O and MSRs via unprivileged…

  • CVE-2021-37315Feb 3, 2023
    risk 0.00cvss epss 0.01

    Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

  • CVE-2021-37316Feb 3, 2023
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.

  • CVE-2021-37317Feb 3, 2023
    risk 0.00cvss epss 0.02

    Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

  • CVE-2022-35401Jan 10, 2023
    risk 0.00cvss epss 0.21

    An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to…

  • CVE-2022-38105Jan 10, 2023
    risk 0.00cvss epss 0.01

    An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packets can lead to a disclosure of sensitive information. An attacker can send a network request…

  • CVE-2022-38393Jan 10, 2023
    risk 0.00cvss epss 0.19

    A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packet can lead to denial of service. An attacker can send a malicious packet to…

  • CVE-2022-44898Dec 14, 2022
    risk 0.00cvss epss 0.00

    The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted…

  • CVE-2020-23648Oct 19, 2022
    risk 0.00cvss epss 0.01

    Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.

  • CVE-2022-36438Oct 18, 2022
    risk 0.00cvss epss 0.00

    AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe…

  • CVE-2022-36439Oct 18, 2022
    risk 0.00cvss epss 0.00

    AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0,…

  • CVE-2021-40556Oct 6, 2022
    risk 0.00cvss epss 0.01

    A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability…

  • CVE-2022-38699Sep 28, 2022
    risk 0.00cvss epss 0.00

    Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging…

  • CVE-2021-41437Sep 26, 2022
    risk 0.00cvss epss 0.01

    An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.

  • CVE-2022-26376Aug 5, 2022
    risk 0.00cvss epss 0.01

    A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this…

  • CVE-2021-43702Jul 5, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

  • CVE-2022-32988Jun 30, 2022
    risk 0.00cvss epss 0.01

    Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist, keyword_rulelist, etc) in every ".asp" page containing a list of stored strings. The following asp files are affected: (1)…

  • CVE-2021-3254May 11, 2022
    risk 0.00cvss epss 0.02

    Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

  • CVE-2022-26674Apr 22, 2022
    risk 0.00cvss epss 0.03

    ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.

  • CVE-2022-26673Apr 22, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.

  • CVE-2022-26672Apr 22, 2022
    risk 0.00cvss epss 0.01

    ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the…

  • CVE-2022-25597Apr 7, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

  • CVE-2022-25596Apr 7, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.

  • CVE-2022-25595Apr 7, 2022
    risk 0.00cvss epss 0.00

    ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.

  • CVE-2022-23973Apr 7, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.

  • CVE-2022-23972Apr 7, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

  • CVE-2022-23971Apr 7, 2022
    risk 0.00cvss epss 0.00

    ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which…

  • CVE-2022-23970Apr 7, 2022
    risk 0.00cvss epss 0.00

    ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in…

  • CVE-2021-45757Mar 23, 2022
    risk 0.00cvss epss 0.02

    ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).

  • CVE-2021-45756Mar 23, 2022
    risk 0.00cvss epss 0.02

    Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

  • CVE-2022-22814Mar 10, 2022
    risk 0.00cvss epss 0.02

    The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

  • CVE-2021-46247Feb 17, 2022
    risk 0.00cvss epss 0.01

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

  • CVE-2021-23863Jan 28, 2022
    risk 0.00cvss epss 0.01

    HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources…

  • CVE-2022-21933Jan 21, 2022
    risk 0.00cvss epss 0.00

    ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

  • CVE-2022-22054Jan 14, 2022
    risk 0.00cvss epss 0.00

    ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.

  • CVE-2021-46109Jan 3, 2022
    risk 0.00cvss epss 0.01

    Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

  • CVE-2021-44158Jan 3, 2022
    risk 0.00cvss epss 0.01

    ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.

  • CVE-2019-20082Dec 28, 2021
    risk 0.00cvss epss 0.02

    ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

  • CVE-2021-41435Nov 19, 2021
    risk 0.00cvss epss 0.06

    A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF…

  • CVE-2021-41436Nov 19, 2021
    risk 0.00cvss epss 0.05

    An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming…

  • CVE-2021-41289Nov 15, 2021
    risk 0.00cvss epss 0.00

    ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BIOS by replacing or filling in the content of the designated Memory DataBuffer, which causing a…

  • CVE-2021-37910Nov 12, 2021
    risk 0.00cvss epss 0.02

    ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames.

  • CVE-2021-42055Oct 18, 2021
    risk 0.00cvss epss 0.00

    ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.

  • CVE-2021-40981Sep 27, 2021
    risk 0.00cvss epss 0.00

    ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.

Page 4 of 6