CVE-2018-17127: Null Pointer Dereference
blockingrequest.cgi on ASUS GT-AC5300 devices through 3.0.0.4.38432738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17127?
CVE-2018-17127 is a vulnerability that allows remote attackers to cause a denial of service on ASUS GT-AC5300 devices.
How does CVE-2018-17127 work?
CVE-2018-17127 exploits a NULL pointer dereference and device crash vulnerability in the blocking_request.cgi script on ASUS GT-AC5300 devices.
What is the severity of CVE-2018-17127?
CVE-2018-17127 has a severity score of 7.5, which is considered high.
Which devices are affected by CVE-2018-17127?
ASUS GT-AC5300 devices running firmware version 3.0.0.4.384_32738 are affected by CVE-2018-17127.
How can I fix CVE-2018-17127?
There is currently no official patch or fix available for CVE-2018-17127. It is recommended to follow the vendor's security advisories for updates.