Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-3080Improper Authentication in Rt-ac68u

Severity
9.8CRITICALNVD
EPSS
53.7%
top 2.00%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 14
Latest updateApr 9

Description

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

CVEListV5asus/rt-ax57earlier3.0.0.4.386_52294
CVEListV5asus/rt-ac68uearlier3.0.0.4.386_51668
CVEListV5asus/rt-ac86uearlier3.0.0.4.386_51915
CVEListV5asus/rt-ax58uearlier3.0.0.4.388_23925
CVEListV5asus/rt-ax88uearlier3.0.0.4.388_24198

🔴Vulnerability Details

3
GHSA
GHSA-6c6m-p94j-g86j: Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device2024-06-14
CVEList
ASUS Router - Improper Authentication2024-06-14
VulnCheck
ASUS Router Authentication Bypass Vulnerability2024

💥Exploits & PoCs

1
Nuclei
ASUS DSL-AC88U - Authentication Bypass

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS ASUS DSL-AC88U Authentication Bypass Attempt (CVE-2024-3080)2025-04-09
CVE-2024-3080 — Improper Authentication in Asus | cvebase