CVE-2024-3912

EUVD-2024-32480
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
asusdsl-n66u_firmware
𝑥
< 1.1.2.3_792
ADP
asusdsl-n12u_c1_firmware
𝑥
< 1.1.2.3_807
ADP
asusdsl-ac55_firmware
𝑥
< 1.1.2.3_999
ADP
asusdsl-n10_c1_firmware
𝑥
≤ *
ADP