PT-2014-4883 · Asus · Rt-Ac56U+8

Publicado

2014-11-04

·

Atualizado

2017-08-29

·

CVE-2014-2718

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions ASUS RT-AC68U versions prior to 3.0.0.4.376.x ASUS RT-AC66R versions prior to 3.0.0.4.376.x ASUS RT-AC66U versions prior to 3.0.0.4.376.x ASUS RT-AC56R versions prior to 3.0.0.4.376.x ASUS RT-AC56U versions prior to 3.0.0.4.376.x ASUS RT-N66R versions prior to 3.0.0.4.376.x ASUS RT-N66U versions prior to 3.0.0.4.376.x ASUS RT-N56R versions prior to 3.0.0.4.376.x ASUS RT-N56U versions prior to 3.0.0.4.376.x
Description The issue allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image, as the routers do not verify the integrity of firmware update information or downloaded updates.
Recommendations For ASUS RT-AC68U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-AC66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-AC66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-AC56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-AC56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-N66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-N66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-N56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later. For ASUS RT-N56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.

Exploit

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2718

Produtos afetados

Rt-Ac56R
Rt-Ac56U
Rt-Ac66R
Rt-Ac66U
Rt-Ac68U
Rt-N56R
Rt-N56U
Rt-N66R
Rt-N66U