Skip to main content

Vendor archive

asus CVEs

Beta · best-effort

273 CVEs tagged to vendor asus49 Critical, 127 High, 94 Medium, 3 Low, 0 Unrated.

CVE-2019-15397

Published Nov 14, 2019

The Asus ZenFone Max 4 Android device with a build fingerprint of asus/WW_Phone/ASUS_X00HD_4:7.1.1/NMF26F/14.2016.1803.373-20180308:user/release-keys contains a pre-installed app…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15396

Published Nov 14, 2019

The Asus ZenFone 3 Android device with a build fingerprint of asus/WW_Phone/ASUS_Z012D:7.0/NRD90M/14.2020.1708.56-20170719:user/release-keys contains a pre-installed app with a pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20336

Published Sep 17, 2019

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10709

Published Sep 4, 2019

AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11063

Published Aug 29, 2019

A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11061

Published Aug 29, 2019

A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself vi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11060

Published Aug 29, 2019

The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14714

Published May 13, 2019

System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14713

Published May 13, 2019

Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL pa…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14711

Published May 13, 2019

Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14992

Published Dec 28, 2018

The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 273 CVEsPage 8 of 11