Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-3080— ASUS Router - Improper Authentication

Quick assessment

Affected
ASUS ZenWiFi XT8
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ASUS routers是中国华硕(ASUS)公司的一款路由器APP。 ASUS Router存在授权问题漏洞,该漏洞源于允许远程攻击者登录设备。

CVSS 9.8 · Critical EPSS 43.46% · P99

Public Exploits 1

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-3080

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASUS Router - Improper Authentication
Source: CVE Program / CVE List V5
Vulnerability Description
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
ASUS Router 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ASUS routers是中国华硕(ASUS)公司的一款路由器APP。 ASUS Router存在授权问题漏洞,该漏洞源于允许远程攻击者登录设备。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
ASUS ZenWiFi XT8 earlier ~ 3.0.0.4.388_24609 -
ASUS ZenWiFi XT8 V2 earlier ~ 3.0.0.4.388_24609 -
ASUS RT-AX88U earlier ~ 3.0.0.4.388_24198 -
ASUS RT-AX58U earlier ~ 3.0.0.4.388_23925 -
ASUS RT-AX57 earlier ~ 3.0.0.4.386_52294 -
ASUS RT-AC86U earlier ~ 3.0.0.4.386_51915 -
ASUS RT-AC68U earlier ~ 3.0.0.4.386_51668 -

II. Public POCs for CVE-2024-3080

# POC Description Source Link Shenlong Link
1 A vulnerability in the ASUS DSL-AC88U router permits unauthorized individuals to bypass authentication.When adding "/js/..%2f%2f" or "/images/..%2f%2e" to the requested URL, it will be recognized as passing the authentication.This vulnerability is part of a broader authentication bypass issue affecting multiple ASUS router models. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3080.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-3080

登录查看更多情报信息。

Vendor Advisories for CVE-2024-3080 (2)

Same Patch Batch · ASUS · 2024-06-14 · 8 CVEs total

CVE-2024-3912 9.8 CRITICAL ASUS Router - Upload arbitrary firmware
CVE-2024-31162 7.2 HIGH ASUS Download Master - OS Command Injection
CVE-2024-31161 7.2 HIGH ASUS Download Master - Arbitrary File Upload
CVE-2024-31163 7.2 HIGH ASUS Download Master - Buffer Overflow
CVE-2024-3079 7.2 HIGH ASUS Router - Stack-based Buffer Overflow
CVE-2024-31160 4.8 MEDIUM ASUS Download Master - Stored XSS
CVE-2024-31159 4.8 MEDIUM ASUS Download Master - Reflected XSS

IV. Related Vulnerabilities

V. Comments for CVE-2024-3080

No comments yet


Leave a comment