PT-2014-4883 · Asus · Rt-Ac56U+8
Published
2014-11-04
·
Updated
2017-08-29
·
CVE-2014-2718
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AC68U versions prior to 3.0.0.4.376.x
ASUS RT-AC66R versions prior to 3.0.0.4.376.x
ASUS RT-AC66U versions prior to 3.0.0.4.376.x
ASUS RT-AC56R versions prior to 3.0.0.4.376.x
ASUS RT-AC56U versions prior to 3.0.0.4.376.x
ASUS RT-N66R versions prior to 3.0.0.4.376.x
ASUS RT-N66U versions prior to 3.0.0.4.376.x
ASUS RT-N56R versions prior to 3.0.0.4.376.x
ASUS RT-N56U versions prior to 3.0.0.4.376.x
Description
The issue allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image, as the routers do not verify the integrity of firmware update information or downloaded updates.
Recommendations
For ASUS RT-AC68U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-AC56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N66R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N66U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N56R versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
For ASUS RT-N56U versions prior to 3.0.0.4.376.x, update the firmware to version 3.0.0.4.376.x or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rt-Ac56R
Rt-Ac56U
Rt-Ac66R
Rt-Ac66U
Rt-Ac68U
Rt-N56R
Rt-N56U
Rt-N66R
Rt-N66U