CVE-2024-3080
ASUS Router - Improper Authentication
Record summary
CVE-2024-3080 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 4, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2024 · Source: CVE List
Affected products and versions
Showing 12 of 15| Product | Source | Version range | Status |
|---|---|---|---|
ASUS RouterBrowse ASUS / ASUS Router | VulnCheck | Version data not supplied | |
RT-AC68UBrowse ASUS / RT-AC68UDefault status: unaffected | CVE List | earlier to ≤ 3.0.0.4.386_51668 | affected |
RT-AC86UBrowse ASUS / RT-AC86UDefault status: unaffected | CVE List | earlier to ≤ 3.0.0.4.386_51915 | affected |
RT-AX57Browse ASUS / RT-AX57Default status: unaffected | CVE List | earlier to ≤ 3.0.0.4.386_52294 | affected |
RT-AX58UBrowse ASUS / RT-AX58UDefault status: unaffected | CVE List | earlier to ≤ 3.0.0.4.388_23925 | affected |
RT-AX88UBrowse ASUS / RT-AX88UDefault status: unaffected | CVE List | earlier to ≤ 3.0.0.4.388_24198 | affected |
ZenWiFi XT8Browse ASUS / ZenWiFi XT8Default status: unaffected | CVE List | earlier to ≤ 3.0.0.4.388_24609 | affected |
ZenWiFi XT8 V2Browse ASUS / ZenWiFi XT8 V2Default status: unaffected | CVE List | earlier to ≤ 3.0.0.4.388_24609 | affected |
rt-ac68u_firmwareBrowse asus / rt-ac68u_firmwareDefault status: unknown | CVE List | Before 3.0.0.4.386_51668 | affected |
rt-ac86u_firmwareBrowse asus / rt-ac86u_firmwareDefault status: unknown | CVE List | Before 3.0.0.4.386_51915 | affected |
rt-ax57_firmwareBrowse asus / rt-ax57_firmwareDefault status: unknown | CVE List | Before 3.0.0.4.386_52294 | affected |
rt-ax58u_firmwareBrowse asus / rt-ax58u_firmwareDefault status: unknown | CVE List | Before 3.0.0.4.388_24762 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALASUS DSL-AC88U - Authentication BypassCVSS 9.8
A vulnerability in the ASUS DSL-AC88U router permits unauthorized individuals to bypass authentication.When adding "/js/..%2f%2f" or "/images/..%2f%2e" to the requested URL, it will be recognized as passing the authentication.This vulnerability is part of a broader authentication bypass issue affecting multiple ASUS router models.
Impact
Attackers can bypass authentication and gain unauthorized access to the router's administrative interface.
Remediation
Update ASUS DSL-AC88U firmware to a version that patches the authentication bypass vulnerability.
Source: ProjectDiscovery