CVE-2014-2718 describes a critical vulnerability in various ASUS RT-series routers, including models like the RT-AC68U and RT-N66U, where firmware updates lack integrity verification. This flaw allows man-in-the-middle attackers to inject and execute arbitrary code during the update process by providing a malicious firmware image. With a CVSS score of 7.1, the vulnerability is highly severe due to its network-based attack vector and high impact on integrity, requiring medium attack complexity but no authentication. While not listed in CISA's KEV catalog and lacking public exploit intelligence like Metasploit or ExploitDB modules, it has garnered some community discussion and media coverage, indicating awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.4.376_3169CPE matchmatch criteria | cpe:2.3:o:t-mobile:tm-ac1900:3.0.0.4.376_3169:*:*:*:*:*:*:* | ||
<= 3.0.0.4.374.xCPE matchmatch criteria | cpe:2.3:o:asus:rt_series_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:C/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.