ASUS Router - Upload arbitrary firmware
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 1.0%
from disclosure to weapon630 days
Published on NVDJun 14
1st PoC+630d
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
ASUS · DSL-AC51ASUS · DSL-AC52ASUS · DSL-AC52UASUS · DSL-AC55ASUS · DSL-AC55UASUS · DSL-AC56UASUS · DSL-AC750ASUS · DSL-N10_C1ASUS · DSL-N10_D1ASUS · DSL-N10P_C1ASUS · DSL-N12E_C1ASUS · DSL-N12U_C1ASUS · DSL-N12U_D1ASUS · DSL-N14UASUS · DSL-N14U_B1ASUS · DSL-N16ASUS · DSL-N16PASUS · DSL-N16UASUS · DSL-N17UASUS · DSL-N55U_C1ASUS · DSL-N55U_D1ASUS · DSL-N66Upublic PoCs found — 1
githubgithub.com/H4rk3nz0/CVE-2024-3912★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.