CRITICAL🇵🇱 Wersja polska

CVE-2017-15655

CVSS 9.6v3.0pub. 2018-01-31upd. 2024-11-21

Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Asus Asuswrt

    OS
    Asus
    < 3.0.0.4.378
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2022-26376CRITICAL9.8PL ✓same product

Uszkodzenie pamięci w module httpd routerów ASUS (Asuswrt/Asuswrt-Merlin)

CVE-2018-20334CRITICAL9.8PL ✓same product

Command injection w ASUSWRT przez parametr fb_email — przejęcie kontroli nad routerem

CVE-2018-6000CRITICAL9.8PL ✓same product

AsusWRT: nieautoryzowany zapis NVRAM umożliwia przejęcie kontroli administracyjnej

CVE-2018-5999CRITICAL9.8PL ✓same product

AsusWRT: pominięcie uwierzytelnienia przy obsłudze żądań POST

CVE-2018-20335HIGH7.5same product

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd s...