Lucene search

K
cve[email protected]CVE-2014-2718
HistoryNov 04, 2014 - 10:55 p.m.

CVE-2014-2718

2014-11-0422:55:06
CWE-345
web.nvd.nist.gov
26
asus
router
firmware
vulnerability
mitm
security

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:C/A:N

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.2%

ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

Affected configurations

NVD
Node
t-mobiletm-ac1900Match3.0.0.4.376_3169
Node
asusrt_series_firmwareRange3.0.0.4.374.x
AND
asusrt-ac56r
OR
asusrt-ac66r
OR
asusrt-ac66u
OR
asusrt-ac68u
OR
asusrt-n56r
OR
asusrt-n56u
OR
asusrt-n66r
OR
asusrt-n66u

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:C/A:N

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.2%

Related for CVE-2014-2718