vendor:
RT-N56U
by:
Jacob Holcomb/Gimppy
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: RT-N56U
Affected Version From: 3.0.0.4.374_979
Affected Version To: 3.0.0.4.374_979
Patch Exists: YES
Related CWE: CVE-2013-6343
CPE: o:asus:rt-n56u
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
ASUS RT-N56U Remote Root Shell Exploit – apps_name
Multiple ASUS routers including the RT-N56U and RT-AC66U have the ability to install supplemental applications. This install process is handled by the routers web server, and is susceptible to multiple Buffer Overflow attacks. Vulnerable Web Page: APP_Installation.asp Vulnerable HTML Parameters: apps_name, apps_flag Vulneralbe Source File: web.c of httpd code *Firmware versions prior to the tested version were vulnerable to this attack.
Mitigation:
Update the firmware to the latest version.