// For flags

CVE-2024-11985

 

Severity Score

4.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router Improper Input Validation' section on the ASUS Security Advisory for more information.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
Multiple
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-11-29 CVE Reserved
  • 2024-12-04 CVE Published
  • 2024-12-04 CVE Updated
  • 2025-04-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Asus
Search vendor "Asus"
Rt-ax55
Search vendor "Asus" for product "Rt-ax55"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax56u
Search vendor "Asus" for product "Rt-ax56u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax56u V2
Search vendor "Asus" for product "Rt-ax56u V2"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax57
Search vendor "Asus" for product "Rt-ax57"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax58u
Search vendor "Asus" for product "Rt-ax58u"
*-
Affected