ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-1160
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c.

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

NVD description · AI analysis pending
9.887% PoC ×5
  • netatalk netatalk
  • netatalk router manager
  • netatalk skynas
  • +1 more
CVE-2022-26376
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7..

A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

NVD description · AI analysis pending
9.81% PoC
  • asus asuswrt
  • asus new gen
  • asus xt8 firmware
  • +1 more
CVE-2022-35401
+2 in the same advisory: …38393 …38105
An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230.

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.

NVD description · AI analysis pending
8.1
group max
21% PoC
  • asus rt-ax82u firmware
CVE-2022-46871
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited.

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

NVD description · AI analysis pending
8.8<1%
  • mozilla firefox
  • mozilla debian linux
CVE-2023-28702
+1 in the same advisory: …28703
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs.

ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.

NVD description · AI analysis pending
8.8
group max
1%
  • asus rt-ac86u firmware
CVE-2023-31195
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute.

ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted ('http') connection, the user's session may be hijacked.

NVD description · AI analysis pending
5.3<1%
  • asus rt-ax3000 firmware
Full article341 words · extracted from securityaffairs.com · click to collapse

ASUS addressed critical vulnerabilities in multiple router models, urging customers to immediately install firmware updates.

ASUS is warning customers to update some router models to the latest firmware to address critical vulnerabilities.

The impacted models are GT6, GT-AXE16000, GT-AX11000 PRO, GT-AX6000, GT-AX11000, GS-AX5400, GS-AX3000, XT9, XT8, XT8 V2, RT-AX86U PRO, RT-AX86U, RT-AX86S, RT-AX82U, RT-AX58U, RT-AX3000, TUF-AX6000, and TUF-AX5400.

The firmware released by the company addressed nine vulnerabilities, including CVE-2023-28702, CVE-2023-28703, CVE-2023-31195, CVE-2022-46871, CVE-2022-38105, CVE-2022-35401, CVE-2018-1160, CVE-2022-38393, and CVE-2022-26376.

The most severe vulnerabilities are two critical issues, below are their descriptions:

  • CVE-2022-26376 is a memory corruption vulnerability that resides in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7. An attacker can trigger the issue by sending a specially-crafted HTTP request to impacted routers leading to memory corruption.
  • CVE-2018-1160 is an out-of-bounds write issue that resides in dsi_opensess.c. The issue impacts Netatalk before 3.1.12 and stems from the lack of bounds checking on attacker-controlled data. A remote, unauthenticated attacker can trigger the issue to execute arbitrary code on vulnerable devices.

“We strongly encourage you to periodically audit both your equipment and your security procedures, as this will ensure that you will be better protected.” reads the advisory published by ASUS. “Update your router to the latest firmware. We strongly recommend that you do so as soon as new firmware is released.”

“Please note, if you choose not to install this new firmware version, we strongly recommend disabling services accessible from the WAN side to avoid potential unwanted intrusions. These services include remote access from WAN, port forwarding, DDNS, VPN server, DMZ, port trigger.” ASUS added.

In case customers cannot immediately install the updates, Asus recommends disabling services accessible from the WAN side to avoid potential unwanted intrusions. These services include remote access from WAN, port forwarding, DDNS, VPN server, DMZ, port trigger.

The vendor also recommends creating distinct, strong passwords for the wireless network and router administration pages.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, backdoor)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/147639/security/asus-fixed-flaws-router-models.html