Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32480 Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
Fixes

Solution

Update following models to version 1.1.2.3_792 or later: DSL-N17U, DSL-N55U_C1, DSL-N55U_D1, DSL-N66U Update following models to version 1.1.2.3_807 or later: DSL-N12U_C1, DSL-N12U_D1, DSL-N14U, DSL-N14U_B1 Update following models to version 1.1.2.3_999 or later: DSL-N16, DSL-AC51, DSL-AC750, DSL-AC52U, DSL-AC55U, DSL-AC56U The following models are no longer maintained, and it is recommended to retire and replace them. DSL-N10_C1, DSL-N10_D1, DSL-N10P_C1, DSL-N12E_C1, ,DSL-N16P, DSL-N16U, DSL-AC52, DSL-AC55 If replacement is not possible in the short term, it is recommended to disable remote access (Web access from WAN), virtual servers (Port forwarding), DDNS, VPN server, DMZ, and port trigger.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T20:26:57.193Z

Reserved: 2024-04-17T07:06:03.258Z

Link: CVE-2024-3912

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.193Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T10:15:10.513

Modified: 2024-11-21T09:30:41.027

Link: CVE-2024-3912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses