First published: Wed Jan 31 2018(Updated: )
Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus asuswrt | <3.0.0.4.378 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15655 refers to multiple buffer overflow vulnerabilities in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X.
CVE-2017-15655 has a severity rating of 9.6, which is considered critical.
To fix CVE-2017-15655, you need to update your Asus asuswrt firmware to version 3.0.0.4.378 or newer.
Routers running Asus asuswrt version <=3.0.0.4.376.X are affected by CVE-2017-15655.
CVE-2017-15655 was not previously disclosed, but it has been fixed in version 3.0.0.4.378.