ASUS has recently released a security advisory in which several ASUS critical router vulnerabilities have been fixed. The vulnerabilities were found to affect multiple ASUS routers with CVEs.
The company has recommended its users upgrade to the latest version of firmware to fix these router vulnerabilities.
ASUS has fixed around 9 CVEs, as reported in the security advisory. The recent one was found to be CVE-2023-28702, and the oldest one was CVE-2018-1160.
| CVE | CVSS Score | CVSS Vector | Description |
| CVE-2023-28702 | 8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Command Injection due to unsanitized parameters in specific web URLs |
| CVE-2023-28703 | 7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | Out of Bounds Write due to insufficient validation of network packet header |
| CVE-2023-31195 | N/A | N/A | Man-In-the-Middle attack due to insecure Cookie attribute |
| CVE-2022-46871 | 8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Outdated Library (libusrsctp) exploitation |
| CVE-2022-38105 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | Out-of-bounds read leads to denial of service |
| CVE-2022-35401 | 8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | Authentication bypass due to expired key |
| CVE-2018-1160 | 9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Out of bounds write in dsi_opensess.c in Netatalk leads to arbitrary code execution |
| CVE-2022-38393 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | Out-of-bounds read leads to denial of service |
| CVE-2022-26376 | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Bounds writing leads to memory corruption |
The list of routers affected by these CVE(s) includes,
ASUS has recommended all of its users patch their routers to prevent attackers.
If upgrading is not required or might affect your configurations, turning off the vulnerable services is recommended.
Looking For an All-in-One Multi-OS Patch Management Platform –
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…