← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-2718

ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

No Active Exploit Signals
CVSS Base Score
7.1
HIGH
EPSS Probability:1.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
t-mobile tm-ac1900 3.0.0.4.376_3169
asus rt_series_firmware all
asus rt-ac56r all
asus rt-ac66r all
asus rt-ac66u all
asus rt-ac68u all
asus rt-n56r all
asus rt-n56u all
asus rt-n66r all
asus rt-n66u all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.103%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2014-04-01T00:00:00
Published2014-11-04T22:00:00
Patch Date2014-10-28
Last Updated2024-08-06T10:21:36

LINK COPIED TO CLIPBOARD