First published: Mon Jan 29 2018(Updated: )
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Dsl-ac51 Firmware | ||
ASUS DSL-AC51 | ||
Asus Dsl-ac52u Firmware | ||
Asus Dsl-ac52u | ||
Asus Dsl-ac55u Firmware | ||
Asus Dsl-ac55u | ||
Asus Dsl-n55u C1 Firmware | ||
Asus Dsl-n55u C1 | ||
Asus Dsl-n55u D1 Firmware | ||
Asus Dsl-n55u D1 | ||
Asus Dsl-ac56u Firmware | ||
Asus Dsl-ac56u | ||
Asus Dsl-n10 C1 Firmware | ||
Asus Dsl-n10 C1 | ||
Asus Dsl-n12u C1 Firmware | ||
Asus Dsl-n12u C1 | ||
Asus Dsl-n12e C1 Firmware | ||
Asus Dsl-n12e C1 | ||
Asus Dsl-n14u Firmware | ||
Asus Dsl-n14u | ||
Asus Dsl-n14u-b1 Firmware | ||
Asus DSL-N14U-B1 | ||
Asus Dsl-n16 Firmware | ||
Asus Dsl-n16 | ||
Asus Dsl-n16u Firmware | ||
Asus Dsl-n16u | ||
Asus Dsl-n17u Firmware | ||
ASUS DSL-N17U | ||
Asus Dsl-n66u Firmware | ||
Asus Dsl-n66u | ||
Asus Dsl-ac750 Firmware | ||
Asus Dsl-ac750 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14699 is a vulnerability found in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers.
CVE-2017-14699 has a severity rating of 6.5 (Medium).
CVE-2017-14699 affects ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers by making them vulnerable to XML external entity (XXE) attacks through the AiCloud feature.
No, ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers are not vulnerable to CVE-2017-14699 as indicated by their respective CPE values.
To fix the CVE-2017-14699 vulnerability, it is recommended to update the firmware of your ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, or DSL-AC750 router to the latest version available from the ASUS website.