← Back

Asuswrt Merlin

asuswrt-merlin

5 CVEs • 30 products

Products (30)

Click to collapse
Toggle
New Gen
new_gen
Rt Ac1200
rt-ac1200
Rt Ac3100
rt-ac3100
Rt Ac3200
rt-ac3200
Rt Ac51u
rt-ac51u
Rt Ac52u
rt-ac52u
Rt Ac53
rt-ac53
Rt Ac5300
rt-ac5300
Rt Ac55u
rt-ac55u
Rt Ac56u
rt-ac56u
Rt Ac58u
rt-ac58u
Rt Ac66u
rt-ac66u
Rt Ac66u B1
rt-ac66u_b1
Rt Ac68p
rt-ac68p
Rt Ac68u
rt-ac68u
Rt Ac88u
rt-ac88u
Rt N12+
rt-n12+
Rt N12d1
rt-n12d1
Rt N12hp
rt-n12hp
Rt N12hp B1
rt-n12hp_b1
Rt N16
rt-n16
Rt N18u
rt-n18u
Rt N300
rt-n300
Rt N56u
rt-n56u
Rt N66u
rt-n66u
Rt Ac1200g
rt_ac1200g
Rt Ac1200gu
rt_ac1200gu
Rt Ac1900p
rt_ac1900p
Rt N12+ Pro
rt_n12+_pro

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Asus
Asuswrt Merlin
19Asuswrt
Et12 FirmwareGt Ax11000 Firmware+16 more
Nov 21, 2024
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruptio...Show more
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.Show less
2Asus
Asuswrt Merlin
2Asus Firmware
Asuswrt Merlin
Nov 21, 2024
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostn...Show more
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.Show less
2Asus
Asuswrt Merlin
2Asus Firmware
Asuswrt Merlin
Nov 21, 2024
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ran...Show more
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.Show less
1Asuswrt Merlin
1Asuswrt Merlin
Nov 21, 2024
Jan 17, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) allows web authenticated attackers to execute code...Show more
Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) allows web authenticated attackers to execute code via a request that updates a setting. In ej_update_variables, the length of the variable action_script is not checked, as long as it includes a "_wan_if" substring.Show less
1Asuswrt Merlin
1Asuswrt Merlin
May 13, 2026
Aug 9, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT...Show more
Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by sending a crafted http GET request packet that includes a long delete_offline_client parameter in the url.Show less