Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.
References
| Link | Resource |
|---|---|
| http://packetstormsecurity.com/files/145921/ASUSWRT-3.0.0.4.382.18495-Session-Hijacking-Information-Disclosure.html | Third Party Advisory VDB Entry |
| http://seclists.org/fulldisclosure/2018/Jan/63 | Exploit Mailing List Third Party Advisory |
| http://sploit.tech/2018/01/16/ASUS-part-I.html | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-01-31 20:29
Updated : 2018-02-21 15:45
NVD link : CVE-2017-15655
Mitre link : CVE-2017-15655
CVE.ORG link : CVE-2017-15655
JSON object : View
Products Affected
asus
- asuswrt
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
