An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
References
Link | Resource |
---|---|
https://jvn.jp/en/vu/JVNVU96079387/ | Third Party Advisory |
https://www.asus.com/event/network/EOL-product/ | Product |
https://www.asus.com/support/ | Not Applicable |
https://jvn.jp/en/vu/JVNVU96079387/ | Third Party Advisory |
https://www.asus.com/event/network/EOL-product/ | Product |
https://www.asus.com/support/ | Not Applicable |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/vu/JVNVU96079387/ - Third Party Advisory | |
References | () https://www.asus.com/event/network/EOL-product/ - Product | |
References | () https://www.asus.com/support/ - Not Applicable |
27 Aug 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE |
03 Jul 2024, 01:42
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 |
21 Nov 2023, 19:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.asus.com/event/network/EOL-product/ - Product | |
References | () https://jvn.jp/en/vu/JVNVU96079387/ - Third Party Advisory | |
References | () https://www.asus.com/support/ - Not Applicable | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CWE | NVD-CWE-Other | |
First Time |
Asus rt-ac87u Firmware
Asus Asus rt-ac87u |
|
CPE | cpe:2.3:o:asus:rt-ac87u_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:asus:rt-ac87u:-:*:*:*:*:*:*:* |
15 Nov 2023, 02:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-15 02:15
Updated : 2024-11-21 08:30
NVD link : CVE-2023-47678
Mitre link : CVE-2023-47678
CVE.ORG link : CVE-2023-47678
JSON object : View
Products Affected
asus
- rt-ac87u
- rt-ac87u_firmware
CWE