Eight vulnerabilities have been identified in various models of ASUS wireless routers, two of which have been assigned a critical severity level (9.8 out of 10). Details on the exploitation of these issues are not yet available; it is known only that the first critical vulnerability (CVE-2024-3080) allows remote access to the device without authentication. The second critical vulnerability (CVE-2024-3912) allows an unauthenticated attacker to upload arbitrary firmware, which can be used to remotely execute any system commands on the device.
The first critical vulnerability affects ASUS ZenWiFi XT8 wireless routers,
RT-AX57, RT-AC86U, RT-AX58U, RT-AC68U, and RT-AX88U, while the second affects ASUS DSL-N17U, DSL-N55U_C1, DSL-N55U_D1, DSL-N66U, DSL-N14U, DSL-N14U_B1, DSL-N12U_C1, DSL-N12U_D1, DSL-N16, DSL-AC51, DSL-AC750, DSL-AC52U, DSL-AC55U, and DSL-AC56U. ASUS has published a firmware update addressing the identified issues for other supported vulnerable devices.
Among the vulnerabilities identified in ASUS devices marked as dangerous, there are also buffer overflows (CVE-2024-3079, CVE-2024-31163) and input validation errors in ASUS Download Master (CVE-2024-31161, CVE-2024-31162), allowing an attacker with access to the device to achieve execution of system commands.
Source: opennet.ru
