CVE Database
/

CVE-2024-3912

Back to search

CVE-2024-3912

Published: Jun 14, 2024

Modified: Aug 1, 2024

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.

VendorProductVersions

ASUS

DSL-N17U

affected
earlier - < 1.1.2.3_792

ASUS

DSL-N55U_C1

affected
earlier - < 1.1.2.3_792

ASUS

DSL-N55U_D1

affected
earlier - < 1.1.2.3_792

ASUS

DSL-N66U

affected
earlier - < 1.1.2.3_792

ASUS

DSL-N12U_C1

affected
earlier - < 1.1.2.3_807

ASUS

DSL-N12U_D1

affected
earlier - < 1.1.2.3_807

ASUS

DSL-N14U

affected
earlier - < 1.1.2.3_807

ASUS

DSL-N14U_B1

affected
earlier - < 1.1.2.3_807

ASUS

DSL-N16

affected
earlier - < 1.1.2.3_999

ASUS

DSL-AC51

affected
earlier - < 1.1.2.3_999

ASUS

DSL-AC750

affected
earlier - < 1.1.2.3_999

ASUS

DSL-AC52U

affected
earlier - < 1.1.2.3_999

ASUS

DSL-AC55U

affected
earlier - < 1.1.2.3_999

ASUS

DSL-AC56U

affected
earlier - < 1.1.2.3_999

ASUS

DSL-N10_C1

affected
All

ASUS

DSL-N10_D1

affected
All

ASUS

DSL-N10P_C1

affected
All

ASUS

DSL-N12E_C1

affected
All

ASUS

DSL-N16P

affected
All

ASUS

DSL-N16U

affected
All

ASUS

DSL-AC52

affected
All

ASUS

DSL-AC55

affected
All

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now