← Back

Asus

asus

272 CVEs • 897 products

Products (897)

Click to collapse
Toggle
Asuswrt
asuswrt
Rt Ac68u
rt-ac68u
Rt N56u
rt-n56u
Rt N66u
rt-n66u

CVEs (272)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asus
1Rt Ax56u Firmware
Nov 21, 2024
Jan 14, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restr...Show more
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.Show less
1Asus
1Rt Ac52u B1 Firmware
Nov 21, 2024
Jan 3, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.
1Asus
1Rt Ax56u Firmware
Nov 21, 2024
Jan 3, 2022
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control t...Show more
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.Show less
1Asus
1Rt N53 Firmware
Nov 21, 2024
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.
1Asus
18Gt Ax11000 Firmware
Rt Ax3000 FirmwareRt Ax55 Firmware+15 more
Nov 21, 2024
Nov 19, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDI...Show more
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.Show less
1Asus
18Gt Ax11000 Firmware
Rt Ax3000 FirmwareRt Ax55 Firmware+15 more
Nov 21, 2024
Nov 19, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZA...Show more
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.Show less
1Asus
1P453uj Bios
Nov 21, 2024
Nov 15, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BIOS by replacing or filling in the content...Show more
ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BIOS by replacing or filling in the content of the designated Memory DataBuffer, which causing a failure of integrity verification and further resulting in a failure to boot.Show less
1Asus
5Gt Axe11000 Firmware
Rt Ax3000 FirmwareRt Ax55 Firmware+2 more
Nov 21, 2024
Nov 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specia...Show more
ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames.Show less
1Asus
1Ux582lr Firmware
Nov 21, 2024
Oct 18, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.
1Asus
1Armoury Crate Lite Service
Nov 21, 2024
Sep 27, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
1Asus
2Gt Ac2900 Firmware
Lyra Mini Firmware
Nov 10, 2025
May 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to u...Show more
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.Show less
1Asus
27Rt Ac1750 B1 Firmware
Rt Ac1900 FirmwareRt Ac1900p Firmware+24 more
Nov 21, 2024
Apr 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between...Show more
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.Show less
1Asus
1Gputweak Ii
Nov 21, 2024
Apr 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoCont...Show more
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoControl.Show less
1Asus
1Gputweak Ii
Nov 21, 2024
Apr 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual a...Show more
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.Show less
1Asus
44Asmb9 Ikvm Firmware
E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 more
Nov 21, 2024
Apr 6, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path...Show more
The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.Show less
1Asus
44Asmb9 Ikvm Firmware
E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 more
Nov 21, 2024
Apr 6, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path tra...Show more
The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.Show less
1Asus
44Asmb9 Ikvm Firmware
E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 more
Nov 21, 2024
Apr 6, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path trav...Show more
The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.Show less
1Asus
44Asmb9 Ikvm Firmware
E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 more
Nov 21, 2024
Apr 6, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path...Show more
The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.Show less
1Asus
3Asmb8 Ikvm Firmware
Z10pe D16 Ws FirmwareZ10pr D16 Firmware
Nov 21, 2024
Apr 6, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of p...Show more
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.Show less
1Asus
3Asmb8 Ikvm Firmware
Z10pe D16 Ws FirmwareZ10pr D16 Firmware
Nov 21, 2024
Apr 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command...Show more
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.Show less