PT-2017-3174 · Asus · Asus Rt-N12+ Pro+20

Bruno Bierbaumer

·

Published

2017-03-08

·

Updated

2017-08-16

·

CVE-2017-6548

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378 RT-AC68W routers with firmware before 3.0.0.4.380.7266 RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488 Asuswrt-Merlin firmware before 380.65 2
Description The issue is caused by buffer overflows in the networkmap component of ASUS router firmware, allowing remote attackers to execute arbitrary code on the router via crafted multicast messages with long host or port values. This can be achieved by forming large strings as values for the host name and port in response to multicast messages.
Recommendations For ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378, update the firmware to version 3.0.0.4.380.7378 or later. For RT-AC68W routers with firmware before 3.0.0.4.380.7266, update the firmware to version 3.0.0.4.380.7266 or later. For RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488, update the firmware to version 3.0.0.4.380.9488 or later. For Asuswrt-Merlin firmware before 380.65 2, update the firmware to version 380.65 2 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02588
CVE-2017-6548

Affected Products

Asus Rt-Ac1750
Asus Rt-Ac1900P
Asus Rt-Ac3200
Asus Rt-Ac51U
Asus Rt-Ac53U
Asus Rt-Ac66U
Asus Rt-Ac68U
Asus Rt-Ac750
Asus Rt-Ac87U
Asus Rt-N11P
Asus Rt-N11P B1
Asus Rt-N12+
Asus Rt-N12+ B1
Asus Rt-N12+ Pro
Asus Rt-N12E B1
Asus Rt-N300
Asus Rt-N300 B1
Asus Rt-N56U
Asus Rt-N600
Asus Rt-N66U
Asuswrt-Merlin