Vulnerability Intelligence Report
ASUS Router - Improper Authentication
CVE-2024-3080
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:41.57%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287: Improper Authentication
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ASUS | ZenWiFi XT8 | earlier <= 3.0.0.4.388_24609 (affected) |
| ASUS | ZenWiFi XT8 V2 | earlier <= 3.0.0.4.388_24609 (affected) |
| ASUS | RT-AX88U | earlier <= 3.0.0.4.388_24198 (affected) |
| ASUS | RT-AX58U | earlier <= 3.0.0.4.388_23925 (affected) |
| ASUS | RT-AX57 | earlier <= 3.0.0.4.386_52294 (affected) |
| ASUS | RT-AC86U | earlier <= 3.0.0.4.386_51915 (affected) |
| ASUS | RT-AC68U | earlier <= 3.0.0.4.386_51668 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TWCERT/CC · CERT · Taiwan |
| Reserved | 2024-03-29T07:18:06 |
| Published | 2024-06-14T02:57:27 |
| Patch Date | 2024-06-14 |
| Last Updated | 2024-08-01T19:32:42 |
Community Chatter & Buzz