Record summary

CVE-2024-3080 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 4, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 15
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.386_51668affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.386_51915affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.386_52294affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.388_23925affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.388_24198affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.388_24609affected

Default status: unaffected

CVE Listearlier to ≤ 3.0.0.4.388_24609affected

Default status: unknown

CVE ListBefore 3.0.0.4.386_51668affected

Default status: unknown

CVE ListBefore 3.0.0.4.386_51915affected

Default status: unknown

CVE ListBefore 3.0.0.4.386_52294affected

Default status: unknown

CVE ListBefore 3.0.0.4.388_24762affected

Nuclei templates

1
ProjectDiscoveryCRITICALASUS DSL-AC88U - Authentication BypassCVSS 9.8

A vulnerability in the ASUS DSL-AC88U router permits unauthorized individuals to bypass authentication.When adding "/js/..%2f%2f" or "/images/..%2f%2e" to the requested URL, it will be recognized as passing the authentication.This vulnerability is part of a broader authentication bypass issue affecting multiple ASUS router models.

Impact

Attackers can bypass authentication and gain unauthorized access to the router's administrative interface.

Remediation

Update ASUS DSL-AC88U firmware to a version that patches the authentication bypass vulnerability.

WeaknessesCWE-287
Authorsritikchaddha
Template tagscvecve2024asusrouterauth-bypasslfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

3