RSS   Podatności dla 'Rt-ac56u firmware'   RSS

2018-10-15
 
CVE-2018-18320

CWE-20
 

 
** DISPUTED ** An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution.

 
 
CVE-2018-18319

CWE-20
 

 
** DISPUTED ** An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution.

 
2017-07-18
 
CVE-2017-11420

CWE-119
 

 
Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code via long device information that is mishandled during a strcat to a device list.

 
2017-07-17
 
CVE-2017-11345

CWE-119
 

 
Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response.

 
 
CVE-2017-11344

CWE-119
 

 
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.

 

 >>> Vendor: Asuswrt-merlin project 34 Produkty
Rt-n12hp b1 firmware
Rt-n56u firmware
Rt-n66u firmware
Rt-ac68u firmware
Rt n12+ pro firmware
Rt ac1900p firmware
Rt-ac5300 firmware
Rt ac1200g firmware
Rt-ac3100 firmware
Rt-n18u firmware
Rt-ac1200 firmware
Rt-n300 firmware
Rt-ac52u firmware
Rt-ac3200 firmware
Rt-ac68p firmware
Rt-n16 firmware
Rt-ac88u firmware
Rt-ac56u firmware
Rt-ac55u firmware
Rt-ac66u firmware
Rt-n12+ firmware
Rt ac1200gu firmware
Rt-n12d1 firmware
Rt-ac66u b1 firmware
Rt-ac58u firmware
Rt-n12hp firmware
Rt-ac53 firmware
Rt-ac51u firmware
Asuswrt-merlin
Rt-ac1900 firmware
Rt-ac2900 firmware
Rt-ac68uf firmware
Rt-ac86u firmware
Rt-ac87 firmware


Copyright 2024, cxsecurity.com

 

Back to Top