T-Mobile Tm-Ac1900 vulnerabilities

7 known vulnerabilities affecting t-mobile/tm-ac1900.

Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2014-9583CRITICALCVSS 10.0PoCv3.0.0.4.376_31692015-01-08
CVE-2014-9583 [CRITICAL] CWE-264 CVE-2014-9583: common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versio common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD packet to UDP port 9999. NOTE:
nvd
CVE-2014-2718HIGHCVSS 7.1v3.0.0.4.376_31692014-11-04
CVE-2014-2718 [HIGH] CWE-345 CVE-2014-2718: ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possi ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.
nvd
CVE-2013-5948HIGHCVSS 8.5PoCv3.0.0.4.376_31692014-04-22
CVE-2013-5948 [HIGH] CWE-78 CVE-2013-5948: The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series router The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter).
nvd
CVE-2014-2925MEDIUMCVSS 4.3v3.0.0.4.376_31692014-04-22
CVE-2014-2925 [MEDIUM] CWE-79 CVE-2014-2925: Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi.
nvd
CVE-2014-2719MEDIUMCVSS 6.3v3.0.0.4.376_31692014-04-22
CVE-2014-2719 [MEDIUM] CWE-200 CVE-2014-2719: Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, whe Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code.
nvd
CVE-2013-1813HIGHCVSS 7.2v3.0.0.4.376_31692013-11-23
CVE-2013-1813 [HIGH] CWE-264 CVE-2013-1813: util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creatin util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
nvd
CVE-2011-2716MEDIUMCVSS 6.8v3.0.0.4.376_31692012-07-03
CVE-2011-2716 [MEDIUM] CWE-20 CVE-2011-2716: The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary co The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
nvd