CVE-2014-2718
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:C/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- t-mobile/tm-ac1900 · asus/rt series firmware
- Source
- cve@mitre.org
References
- http://dnlongen.blogspot.com/2014/10/CVE-2014-2718-Asus-RT-MITM.htmlExploit
- http://packetstormsecurity.com/files/128904/ASUS-Router-Man-In-The-Middle.htmlExploit
- http://seclists.org/fulldisclosure/2014/Oct/122Exploit
- http://www.securityfocus.com/bid/70791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98316
- https://support.t-mobile.com/docs/DOC-21994
- http://dnlongen.blogspot.com/2014/10/CVE-2014-2718-Asus-RT-MITM.htmlExploit
- http://packetstormsecurity.com/files/128904/ASUS-Router-Man-In-The-Middle.htmlExploit
- http://seclists.org/fulldisclosure/2014/Oct/122Exploit
- http://www.securityfocus.com/bid/70791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98316
- https://support.t-mobile.com/docs/DOC-21994
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.