CVE-2021-3166
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, resulting in a persistent outage of those services.
Se detectó un problema en los dispositivos ASUS DSL-N14U-B1 versión 1.1.2.3_805. Un atacante puede cargar contenido de archivo arbitrario como una actualización de firmware cuando el nombre de archivo Settings_DSL-N14U-B1.trx es usado. Una vez que es cargado este archivo, unas medidas de cierre en una amplia gama de servicios son desencadenadas como si fuera una actualización real, resultando en una interrupción persistente de esos servicios
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-18 CVE Reserved
- 2021-01-18 CVE Published
- 2022-11-18 First Exploit
- 2024-08-03 CVE Updated
- 2024-10-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/kaisersource/CVE-2021-3166 | 2022-11-18 | |
https://github.com/kaisersource/kaisersource.github.io/blob/main/_posts/2021-01-17-dsl-n14u.md | 2024-08-03 | |
https://kaisersource.github.io/dsl-n14u | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Asus Search vendor "Asus" | Dsl-n14u B1 Firmware Search vendor "Asus" for product "Dsl-n14u B1 Firmware" | 1.1.2.3_805 Search vendor "Asus" for product "Dsl-n14u B1 Firmware" and version "1.1.2.3_805" | - |
Affected
| in | Asus Search vendor "Asus" | Dsl-n14u B1 Search vendor "Asus" for product "Dsl-n14u B1" | - | - |
Safe
|