Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-3912— ASUS Router - Upload arbitrary firmware

CVSS 9.8 · Critical EPSS 3.93% · P88
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-3912

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASUS Router - Upload arbitrary firmware
Source: NVD (National Vulnerability Database)
Vulnerability Description
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
危险类型文件的不加限制上传
Source: NVD (National Vulnerability Database)
Vulnerability Title
ASUS Router 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ASUS routers是中国华硕(ASUS)公司的一款路由器APP。 ASUS Router存在代码问题漏洞。远程攻击者利用该漏洞在设备上执行任意系统命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
ASUSDSL-N17U earlier ~ 1.1.2.3_792 -
ASUSDSL-N55U_C1 earlier ~ 1.1.2.3_792 -
ASUSDSL-N55U_D1 earlier ~ 1.1.2.3_792 -
ASUSDSL-N66U earlier ~ 1.1.2.3_792 -
ASUSDSL-N12U_C1 earlier ~ 1.1.2.3_807 -
ASUSDSL-N12U_D1 earlier ~ 1.1.2.3_807 -
ASUSDSL-N14U earlier ~ 1.1.2.3_807 -
ASUSDSL-N14U_B1 earlier ~ 1.1.2.3_807 -
ASUSDSL-N16 earlier ~ 1.1.2.3_999 -
ASUSDSL-AC51 earlier ~ 1.1.2.3_999 -
ASUSDSL-AC750 earlier ~ 1.1.2.3_999 -
ASUSDSL-AC52U earlier ~ 1.1.2.3_999 -
ASUSDSL-AC55U earlier ~ 1.1.2.3_999 -
ASUSDSL-AC56U earlier ~ 1.1.2.3_999 -
ASUSDSL-N10_C1 All -
ASUSDSL-N10_D1 All -
ASUSDSL-N10P_C1 All -
ASUSDSL-N12E_C1 All -
ASUSDSL-N16P All -
ASUSDSL-N16U All -
ASUSDSL-AC52 All -
ASUSDSL-AC55 All -

II. Public POCs for CVE-2024-3912

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-3912

登录查看更多情报信息。

Same Patch Batch · ASUS · 2024-06-14 · 8 CVEs total

CVE-2024-30809.8 CRITICALASUS Router - Improper Authentication
CVE-2024-311627.2 HIGHASUS Download Master - OS Command Injection
CVE-2024-311617.2 HIGHASUS Download Master - Arbitrary File Upload
CVE-2024-311637.2 HIGHASUS Download Master - Buffer Overflow
CVE-2024-30797.2 HIGHASUS Router - Stack-based Buffer Overflow
CVE-2024-311604.8 MEDIUMASUS Download Master - Stored XSS
CVE-2024-311594.8 MEDIUMASUS Download Master - Reflected XSS

IV. Related Vulnerabilities

V. Comments for CVE-2024-3912

No comments yet


Leave a comment