Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HAsus Asuswrt
OSAsus< 3.0.0.4.378
Related vulnerabilities
Uszkodzenie pamięci w module httpd routerów ASUS (Asuswrt/Asuswrt-Merlin)
Command injection w ASUSWRT przez parametr fb_email — przejęcie kontroli nad routerem
AsusWRT: nieautoryzowany zapis NVRAM umożliwia przejęcie kontroli administracyjnej
AsusWRT: pominięcie uwierzytelnienia przy obsłudze żądań POST
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd s...