CVE-2013-6343
ASUS RT-N56U - Remote Buffer Overflow (ROP)
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.
Múltiples desbordamientos de búfer en web.c de httpd en routers ASUS RT-N56U y RT-AC66U con firmware 3.0.0.4.374_979 permite a atacantes remotos ejecutar código arbitrario a través de parámetros (1) apps_name o (2) apps_flag hacia APP_Installation.asp.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-11-01 CVE Reserved
- 2014-01-19 CVE Published
- 2014-01-19 First Exploit
- 2024-01-20 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/102267 | Vdb Entry | |
http://www.securityfocus.com/bid/65046 | Vdb Entry | |
https://support.t-mobile.com/docs/DOC-21994 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31033 | 2014-01-19 | |
http://infosec42.blogspot.com/2014/01/exploit-asus-rt-n56u-remote-root-shell.html | 2024-08-06 | |
http://www.exploit-db.com/exploits/31033 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Asus Search vendor "Asus" | Tm-ac1900 Firmware Search vendor "Asus" for product "Tm-ac1900 Firmware" | 3.0.0.4..374_979 Search vendor "Asus" for product "Tm-ac1900 Firmware" and version "3.0.0.4..374_979" | - |
Affected
| in | Asus Search vendor "Asus" | Tm-ac1900 Search vendor "Asus" for product "Tm-ac1900" | - | - |
Safe
|
Asus Search vendor "Asus" | Rt-n56u Firmware Search vendor "Asus" for product "Rt-n56u Firmware" | 3.0.0.4..374_979 Search vendor "Asus" for product "Rt-n56u Firmware" and version "3.0.0.4..374_979" | - |
Affected
| in | Asus Search vendor "Asus" | Rt-n56u Search vendor "Asus" for product "Rt-n56u" | - | - |
Safe
|
Asus Search vendor "Asus" | Rt-ac66u Firmware Search vendor "Asus" for product "Rt-ac66u Firmware" | 3.0.0.4..374_979 Search vendor "Asus" for product "Rt-ac66u Firmware" and version "3.0.0.4..374_979" | - |
Affected
| in | Asus Search vendor "Asus" | Rt-ac66u Search vendor "Asus" for product "Rt-ac66u" | - | - |
Safe
|