Skip to main content

Vendor archive

asus CVEs

Beta · best-effort

273 CVEs tagged to vendor asus49 Critical, 127 High, 94 Medium, 3 Low, 0 Unrated.

CVE-2018-18537

Published Dec 26, 2018

The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-18536

Published Dec 26, 2018

The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of wa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18535

Published Dec 26, 2018

The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18291

Published Oct 14, 2018

A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18287

Published Oct 14, 2018

On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp pag…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17127

Published Sep 17, 2018

blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a req…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17023

Published Sep 13, 2018

Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack the authentication of administr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17022

Published Sep 13, 2018

Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17021

Published Sep 13, 2018

Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17020

Published Sep 13, 2018

ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0647

Published Sep 7, 2018

Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication of administrators via unspecif…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15887

Published Aug 27, 2018

Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via s…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6558

Published Jul 13, 2018

A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_sc…

CVSS 9.8 · Critical

CVE-2016-6557

Published Jul 13, 2018

In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was in…

CVSS 8.8 · High

CVE-2018-0583

Published May 14, 2018

Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0582

Published May 14, 2018

Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0581

Published May 14, 2018

Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15656

Published Jan 31, 2018

Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15655

Published Jan 31, 2018

Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 273 CVEsPage 9 of 11