← Back

Asus

asus

272 CVEs • 897 products

Products (897)

Click to collapse
Toggle
Asuswrt
asuswrt
Rt Ac68u
rt-ac68u
Rt N56u
rt-n56u
Rt N66u
rt-n66u

CVEs (272)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator priv...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack t...Show more
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to ex...Show more
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection...Show more
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to...Show more
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to exec...Show more
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac66u B1 Firmware
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
1Asus
1Rt Ax88u Firmware
Nov 21, 2024
Jul 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with...Show more
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.Show less
1Asus
1Rt Ax88u Firmware
Nov 21, 2024
Jul 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of...Show more
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.Show less
1Asus
1Rt Ax88u Firmware
Nov 21, 2024
Jul 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a st...Show more
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.Show less
1Asus
2Armoury Crate
Setupasusservices
Nov 21, 2024
Jul 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
1Asus
2Rt Ac86u Firmware
Rt Ax56u V2 Firmware
Nov 21, 2024
Jul 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CO...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.Show less
1Asus
2Rt Ac86u Firmware
Rt Ax56u V2 Firmware
Nov 21, 2024
Jul 21, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529. Show less
1Asus
1Rt Ax3000 Firmware
Jan 3, 2025
Jun 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricke...Show more
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted ('http') connection, the user's session may be hijacked.Show less
1Asus
1Rt N10lx Firmware
Nov 21, 2024
Jun 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
1Asus
1Rt N10lx Firmware
Nov 21, 2024
Jun 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyw...Show more
A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyword List text field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Asus
1Rt N10lx Firmware
Jan 6, 2025
Jun 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Jun 2, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vuln...Show more
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Jun 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary...Show more
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.Show less
1Asus
1Rt Ac51u Firmware
Jan 30, 2025
May 2, 2023
N/A· v4
5.2 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to...Show more
A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or HTML via a malicious network request.Show less