ASUS WebStorage是中国华硕(ASUS)公司的一种在线存储服务。 ASUS WebStorage 存在安全漏洞,该漏洞源于在 APP 源代码中有一个硬编码的 API Token。未经身份验证的远程攻击者可以使用此令牌与服务器建立连接并对一般用户帐户进行登录尝试。成功登录到普通用户帐户允许攻击者访问、修改或删除此用户帐户信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ASUS | WebStorage | unspecified ~ 3.10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-26674 | 9.8 CRITICAL | ASUS RT-AX88U - Format String |
| CVE-2022-26673 | 5.4 MEDIUM | ASUS RT-AX88U - Stored XSS |
No comments yet