ASUS warns of critical remote authentication bypass on 7 routers
ID: 971c2dd1-8c0f-5595-9248-78a4c50e896b
STIX ID: report--971c2dd1-8c0f-5595-9248-78a4c50e896b
Feed Name: Bleeping Computer
ASUS released firmware updates addressing critical vulnerabilities in multiple router models, including CVE-2024-3080 (9.8, authentication bypass enabling unauthenticated remote takeover), CVE-2024-3912 (9.8, arbitrary firmware upload), and CVE-2024-3079 (7.2, buffer overflow requiring admin); users are advised to update firmware, harden credentials, and disable remote admin/WAN access and other services if immediate patching is not possible. The vendor also updated the Download Master utility (v3.1.0.114) to fix several medium-to-high severity issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
