CVE-2017-6548 describes buffer overflow vulnerabilities in the networkmap component of numerous ASUS RT series routers and Asuswrt-Merlin firmware. These flaws allow remote, unauthenticated attackers to execute arbitrary code on affected devices by sending crafted multicast messages with excessively long host or port values. With a CVSS score of 9.8 (Critical), the vulnerability poses a significant risk, enabling complete compromise of the router with high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available on ExploitDB, and the vulnerability has garnered substantial community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.4.380.6038CPE matchmatch criteria | cpe:2.3:o:asus:rt-ac53_firmware:3.0.0.4.380.6038:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.