Vulnerabilities
Vulnerable Software
Asus:  Security Vulnerabilities
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
CVSS Score
8.8
EPSS Score
0.005
Published
2022-04-07
ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.
CVSS Score
8.8
EPSS Score
0.006
Published
2022-04-07
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
CVSS Score
6.5
EPSS Score
0.004
Published
2022-04-07
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
CVSS Score
8.8
EPSS Score
0.006
Published
2022-04-07
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.
CVSS Score
8.8
EPSS Score
0.009
Published
2022-04-07
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
CVSS Score
9.8
EPSS Score
0.012
Published
2022-03-23
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).
CVSS Score
7.5
EPSS Score
0.011
Published
2022-03-23
The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
CVSS Score
9.8
EPSS Score
0.023
Published
2022-03-10
ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate the path before deletion, an unauthenticated local attacker can create an unexpected symbolic link to system file path, to delete arbitrary system files and disrupt system service.
CVSS Score
7.7
EPSS Score
0.003
Published
2022-03-01
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.
CVSS Score
7.5
EPSS Score
0.012
Published
2022-02-17


Contact Us

Shodan ® - All rights reserved