Asus Gt-Ac5300 Firmware vulnerabilities
5 known vulnerabilities affecting asus/gt-ac5300_firmware.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2018-17127HIGHCVSS 7.5≤ 3.0.0.4.384.327382018-09-17
CVE-2018-17127 [HIGH] CWE-476 CVE-2018-17127: blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.
nvd
CVE-2018-17020HIGHCVSS 7.5≤ 3.0.0.4.384_327382018-09-13
CVE-2018-17020 [HIGH] CVE-2018-17020: ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a den
ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line.
nvd
CVE-2018-17023HIGHCVSS 8.8≤ 3.0.0.4.384_327382018-09-13
CVE-2018-17023 [HIGH] CWE-352 CVE-2018-17023: Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.
Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm.
nvd
CVE-2018-17022HIGHCVSS 7.2≤ 3.0.0.4.384_327382018-09-13
CVE-2018-17022 [HIGH] CWE-787 CVE-2018-17022: Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote att
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c u
nvd
CVE-2018-17021MEDIUMCVSS 6.1≤ 3.0.0.4.384_327382018-09-13
CVE-2018-17021 [MEDIUM] CWE-79 CVE-2018-17021: Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
nvd