ASUS Routers Vulnerable to Arbitrary Firmware Upload Attack

CVE-2024-3912
9.8CRITICAL

Key Information

Vendor
Asus
Status
Dsl-n17u
Dsl-n55u C1
Dsl-n55u D1
Dsl-n66u
Vendor
CVE Published:
14 June 2024

Summary

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.

Affected Version(s)

DSL-N17U < 1.1.2.3_792

DSL-N55U_C1 < 1.1.2.3_792

DSL-N55U_D1 < 1.1.2.3_792

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.