CVE-2018-17022: Buffer Overflow
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.38432738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long shpath0 value and then sending an appGet.cgi?hook=selectlist("StoragexSharedPath") request, because ejselectlist in router/httpd/web.c uses strcpy.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17022?
CVE-2018-17022 is a stack-based buffer overflow vulnerability on the ASUS GT-AC5300 router.
How does CVE-2018-17022 impact the affected devices?
CVE-2018-17022 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact.
What is the severity of CVE-2018-17022?
CVE-2018-17022 has a severity rating of 7.2 (high).
How can I fix CVE-2018-17022?
To fix CVE-2018-17022, update your ASUS GT-AC5300 router firmware to version 3.0.0.4.384_32739 or later.
Where can I find more information about CVE-2018-17022?
You can find more information about CVE-2018-17022 at this reference: https://github.com/PAGalaxyLab/VulInfo/blob/master/ASUS/buffer_overflow/ASUS%20GT-AC5300%20stack%20overflow.MD