ASUS Critical Vulnerabilities Let Attackers Execute Arbitrary Commands
ID: 9bea8314-71e7-5709-b5f3-02660067c2bd
STIX ID: report--9bea8314-71e7-5709-b5f3-02660067c2bd
Feed Name: GBHackers
ASUS has released an advisory for two high-severity injection/execution vulnerabilities (CVE-2024-12912 and CVE-2024-13062) in the AiCloud feature of multiple router models that can allow authenticated attackers to execute arbitrary commands (CVSS 7.2). ASUS advises immediate firmware updates to fixed versions (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102 series) and provides interim mitigations such as strong passwords, enabling AiCloud password protection, and disabling internet-facing services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
