XML External Entity Vulnerabilities in ASUS DSL Routers
CVE-2017-14699
6.5MEDIUM
What is CVE-2017-14699?
The AiCloud feature present in several ASUS DSL routers is susceptible to multiple XML External Entity (XXE) vulnerabilities. These issues allow remote authenticated users to exploit the routers by sending crafted Document Type Definitions (DTD) in specific requests. By leveraging these vulnerabilities in an UPDATEACCOUNT or PROPFIND request, attackers can read arbitrary files on the system, potentially exposing sensitive information and impacting the integrity and confidentiality of the device's operation.