Severity
7.5HIGH
EPSS
1.3%
top 19.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateOct 9

Description

The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score 7.4 (Availability impacts). CVSS vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDasus/hg100_firmware1.05.12
CVEListV5asus/hg100_firmwareup to 1.05.12

🔴Vulnerability Details

2
GHSA
GHSA-cj49-fqj3-gccc: The web api server on Port 8080 of ASUS HG100 firmware up to 12022-05-24
CVEList
HG100 contains an Uncontrolled Resource Consumption vulnerability2019-08-29

💥Exploits & PoCs

1
Exploit-DB
GLPI GZIP(Py3) 9.4.5 - RCE2023-10-09
CVE-2019-11060 (HIGH CVSS 7.5) | The web api server on Port 8080 of | cvebase.io