CVE-2014-2718: High severity asus tm-ac1900 vulnerability
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2718?
CVE-2014-2718 has been categorized as a critical vulnerability due to the potential for man-in-the-middle attacks on affected routers.
How do I fix CVE-2014-2718?
To fix CVE-2014-2718, users should update their ASUS RT series router firmware to version 3.0.0.4.376.x or later.
Which devices are affected by CVE-2014-2718?
Devices affected by CVE-2014-2718 include various ASUS RT series routers such as RT-AC68U, RT-AC66R, RT-AC66U, and others prior to the specified firmware version.
What type of attack does CVE-2014-2718 allow?
CVE-2014-2718 allows attackers to perform man-in-the-middle (MITM) attacks by exploiting the lack of integrity verification for firmware updates.
Is there a workaround for CVE-2014-2718?
There are no effective workarounds for CVE-2014-2718, and updating the firmware to a fixed version is the recommended solution.