PT-2017-3174 · Asus · Asus Rt-N12+ Pro+20
Bruno Bierbaumer
·
Published
2017-03-08
·
Updated
2017-08-16
·
CVE-2017-6548
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378
RT-AC68W routers with firmware before 3.0.0.4.380.7266
RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488
Asuswrt-Merlin firmware before 380.65 2
Description
The issue is caused by buffer overflows in the networkmap component of ASUS router firmware, allowing remote attackers to execute arbitrary code on the router via crafted multicast messages with long host or port values. This can be achieved by forming large strings as values for the host name and port in response to multicast messages.
Recommendations
For ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378, update the firmware to version 3.0.0.4.380.7378 or later.
For RT-AC68W routers with firmware before 3.0.0.4.380.7266, update the firmware to version 3.0.0.4.380.7266 or later.
For RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488, update the firmware to version 3.0.0.4.380.9488 or later.
For Asuswrt-Merlin firmware before 380.65 2, update the firmware to version 380.65 2 or later.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ac1750
Asus Rt-Ac1900P
Asus Rt-Ac3200
Asus Rt-Ac51U
Asus Rt-Ac53U
Asus Rt-Ac66U
Asus Rt-Ac68U
Asus Rt-Ac750
Asus Rt-Ac87U
Asus Rt-N11P
Asus Rt-N11P B1
Asus Rt-N12+
Asus Rt-N12+ B1
Asus Rt-N12+ Pro
Asus Rt-N12E B1
Asus Rt-N300
Asus Rt-N300 B1
Asus Rt-N56U
Asus Rt-N600
Asus Rt-N66U
Asuswrt-Merlin