Asuswrt
Vendor:
First CVE: Jan 22, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 89% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Asuswrt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Aug 5, 2022
1,453 days ago
CVE Severity & Scoring
Asuswrt10 CVEs
50%
50%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6000CRITICAL An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configur | Jan 22, 2018 | 9.8 | 89 | NO | YES |
CVE-2018-5999CRITICAL An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fa | Jan 22, 2018 | 9.8 | 89 | NO | YES |
CVE-2018-20334CRITICAL An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email pa | Mar 20, 2020 | 9.8 | 32 | NO | NO |
CVE-2022-26376CRITICAL A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted H | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-15655CRITICAL Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was n | Jan 31, 2018 | 9.6 | 29 | NO | NO |
CVE-2017-15656HIGH Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt. | Jan 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-15653HIGH Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any ac | Jan 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-20335HIGH An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI. | Mar 20, 2020 | 7.5 | 25 | NO | NO |
CVE-2018-20333HIGH An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps | Mar 20, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-15654HIGH Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access. | Jan 31, 2018 | 8.3 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
20.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
20.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Asuswrt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0.4.384.20308 | 3 | 8.3 | 2.1% | 0 | 0 |