PT-2017-11946 · Asus · Rt-N56U+27
Published
2017-07-16
·
Updated
2017-12-20
·
CVE-2017-11345
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Asuswrt-Merlin firmware for ASUS devices versions (affected versions not specified)
ASUS firmware for ASUS RT-AC5300, RT AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT AC1200GU, RT AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP B1, RT-N12D1, RT-N12+, RT N12+ PRO, RT-N16, and RT-N300 devices versions (affected versions not specified)
Description
A stack buffer overflow issue in the networkmap of Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for various ASUS router models allows remote attackers to execute arbitrary code on the router. This can be achieved by hosting a crafted device description XML document that includes a
serviceType element at a URL specified within a Location header in an SSDP response.Recommendations
For Asuswrt-Merlin firmware for ASUS devices, at the moment, there is no information about a newer version that contains a fix for this issue.
For ASUS firmware for ASUS RT-AC5300, RT AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT AC1200GU, RT AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP B1, RT-N12D1, RT-N12+, RT N12+ PRO, RT-N16, and RT-N300 devices, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asuswrt-Merlin
Rt-Ac1200
Rt-Ac1200G
Rt-Ac1900P
Rt-Ac3100
Rt-Ac3200
Rt-Ac51U
Rt-Ac52U
Rt-Ac53
Rt-Ac5300
Rt-Ac55U
Rt-Ac56U
Rt-Ac58U
Rt-Ac66U
Rt-Ac66U B1
Rt-Ac68P
Rt-Ac68U
Rt-Ac88U
Rt-N12+
Rt-N12+ Pro
Rt-N12D1
Rt-N12Hp
Rt-N12Hp B1
Rt-N16
Rt-N18U
Rt-N300
Rt-N56U
Rt-N66U