PT-2014-4883 · Asus · Rt-Ac56U+8
Publicado
2014-11-04
·
Atualizado
2017-08-29
·
CVE-2014-2718
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AC68U versions prior to 3.0.0.4.376.x
ASUS RT-AC66R versions prior to 3.0.0.4.376.x
ASUS RT-AC66U versions prior to 3.0.0.4.376.x
ASUS RT-AC56R versions prior to 3.0.0.4.376.x
ASUS RT-AC56U versions prior to 3.0.0.4.376.x
ASUS RT-N66R versions prior to 3.0.0.4.376.x
ASUS RT-N66U versions prior to 3.0.0.4.376.x
ASUS RT-N56R versions prior to 3.0.0.4.376.x
ASUS RT-N56U versions prior to 3.0.0.4.376.x
Description
The issue allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image, as the routers do not verify the integrity of firmware update information or downloaded updates.
Recommendations
For ASUS RT-AC68U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
Exploit
Correção
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rt-Ac56R
Rt-Ac56U
Rt-Ac66R
Rt-Ac66U
Rt-Ac68U
Rt-N56R
Rt-N56U
Rt-N66R
Rt-N66U