Site icon TheCyberThrone

Asus addresses several critical vulnerabilities

Advertisements

ASUS has released patches for addressing several vulnerabilities resides in its router products.

The first one is a critical remote authentication bypass vulnerability, tracked as CVE-2024-3080 with a CVSS score of 9.8, which is an authentication bypass issue that a remote attacker can exploit to log into the device without authentication.

Advertisements

The flaw impacts the following models:

The company released the firmware update to address the issue in its routers

Asus also addressed a critical upload arbitrary firmware flaw, tracked as CVE-2024-3912 with a CVSS score of 9.8, is an unauthenticated, remote attacker can exploit the flaw to execute system commands on the vulnerable device.

Some impacted models will not receive the firmware updates because they have reached the end-of-life.

If those routers are not able to get replaced, it is recommended to close it. Remote access (Web access from WAN), virtual server (Port forwarding), DDNS, VPN server, DMZ, port trigger

Exit mobile version