Asus
Asus Hg100 Firmware: vulnerabilidades y CVE
Asus Hg100 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-15912 | Alta (7.5) | 1.3% | — | 20 dic 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. |
| CVE-2019-15911 | Crítica (9.8) | 0.84% | — | 20 dic 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause… |
| CVE-2019-15910 | Alta (7.5) | 1.3% | — | 20 dic 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. |
| CVE-2019-11061 | Alta (8.1) | 4.0% | — | 29 ago 2019 | A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via… |
| CVE-2019-11060 | Alta (7.5) | 3.0% | — | 29 ago 2019 | The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP… |
| CVE-2018-11492 | Alta (7.5) | 11% | — | 10 ago 2018 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. |
| CVE-2018-11491 | Crítica (9.8) | 6.7% | — | 25 jul 2018 | ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. |