Liikenne- ja viestintäviraston Kyberturvallisuuskeskuksen päivittäisessä haavoittuvuuskoosteessa (2024-06-14) mainittu haavoittuvuuksista Asus reitittimissä.
KOKO TIEDOTE:
Critical Vulnerabilities Identified in multiple ASUS Routers
URL:
TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center-ASUS Router - Improper Authentication
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
CVEs: CVE-2024-3080, CVE-2024-3079, CVE-2024-3912
See also:
-
TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center-ASUS Router - Upload arbitrary firmware
-
TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center-ASUS Router - Stack-based Buffer Overflow
Critical vulnerabilities have been identified in multiple ASUS router models.
The critical severity vulnerabilities allow an unauthenticated remote attacker
to log into an affected device or to execute arbitrary system commands.
Another high severity vulnerability was also identified that allows a remote
attacker with administrative privileges to execute arbitrary commands on an
affected system. Both of the vulnerabilities have been fixed by the vendors
security updates. One or more of the vulnerabilities affects the following
models and versions:
ZenWiFi XT8 version 3.0.0.4.388_24609 and earlier
ZenWiFi XT8 version V2 3.0.0.4.388_24609 and earlier
RT-AX88U version 3.0.0.4.388_24198 and earlier
RT-AX58U version 3.0.0.4.388_23925 and earlier
RT-AX57 version 3.0.0.4.386_52294 and earlier
RT-AC86U version 3.0.0.4.386_51915 and earlier
RT-AC68U version 3.0.0.4.386_51668 and earlier
DSL-N17U, DSL-N55U_C1, DSL-N55U_D1, DSL-N66U versions below 1.1.2.3_792
DSL-N12U_C1, DSL-N12U_D1, DSL-N14U, DSL-N14U_B1 versions below 1.1.2.3_807
DSL-N16, DSL-AC51, DSL-AC750, DSL-AC52U, DSL-AC55U, DSL-AC56U versions below
1.1.2.3_999
DSL-N10_C1, DSL-N10_D1, DSL-N10P_C1, DSL-N12E_C1, ,DSL-N16P, DSL-N16U,
DSL-AC52, DSL-AC55 all versions, models are end-of-life and vendor recommends
retiring the devices.
EDIT: Laitoin saman tuonne ASUS ketjuun.
Asuswrt-Merlin 3004.388.6 julkaistu. https://www.snbforums.com/threads/asuswrt-merlin-3004-388-6-is-now-available.88559/ 3004.388.6 (20-Jan-2024) - NOTE: Since Asus provided GPL code for the RT-AX56U, this model will exceptionally be included with this release, despite still being considered...
bbs.io-tech.fi