CVE-2017-11344

Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac5300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac5300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt_ac1900p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt_ac1900p_:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac68u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac68u:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac68p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac68p:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac88u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac88u:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac66u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac66u:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac66u_b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac66u_b1:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac58u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac58u:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac56u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac56u:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac55u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac55u:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac52u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac52u:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac51u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac51u:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n18u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n18u:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n66u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n66u:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n56u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n56u:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac3200:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac3100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac3100:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt_ac1200gu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt_ac1200gu:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt_ac1200g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt_ac1200g:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac1200:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-ac53_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-ac53:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n12hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n12hp:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n12hp_b1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n12hp_b1:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n12d1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n12d1:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n12\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n12\+:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt_n12\+_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt_n12\+_pro:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n16_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n16:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:asuswrt-merlin_project:rt-n300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asuswrt-merlin_project:rt-n300:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:07

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2017/07/14/3 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2017/07/14/3 - Mailing List, Third Party Advisory
References () https://asuswrt.lostrealm.ca/changelog - () https://asuswrt.lostrealm.ca/changelog -

Information

Published : 2017-07-17 13:18

Updated : 2024-11-21 03:07


NVD link : CVE-2017-11344

Mitre link : CVE-2017-11344

CVE.ORG link : CVE-2017-11344


JSON object : View

Products Affected

asuswrt-merlin_project

  • rt-ac66u_b1
  • rt_ac1900p_firmware
  • rt-ac1200
  • rt-n18u
  • rt-n12\+_firmware
  • rt-n300_firmware
  • rt-ac55u
  • rt_ac1200gu_firmware
  • rt-ac53
  • rt-ac1200_firmware
  • rt-n16_firmware
  • rt-ac68u
  • rt-ac56u
  • rt-n16
  • rt-ac66u
  • rt-ac56u_firmware
  • rt-ac5300
  • rt-n56u_firmware
  • rt-ac53_firmware
  • rt-n12d1
  • rt-ac52u_firmware
  • rt_ac1200gu
  • rt-ac51u
  • rt-ac66u_firmware
  • rt-ac66u_b1_firmware
  • rt-ac58u
  • rt-ac88u_firmware
  • rt-n56u
  • rt-ac68p
  • rt_ac1200g_firmware
  • rt_ac1900p_
  • rt-ac3100
  • rt-n66u_firmware
  • rt-n18u_firmware
  • rt-ac68u_firmware
  • rt-ac3100_firmware
  • rt-ac52u
  • rt-ac51u_firmware
  • rt-ac5300_firmware
  • rt-n12\+
  • rt-n12hp_b1
  • rt-ac3200_firmware
  • rt_n12\+_pro
  • rt_ac1200g
  • rt-n12d1_firmware
  • rt_n12\+_pro_firmware
  • rt-ac68p_firmware
  • rt-ac58u_firmware
  • rt-ac88u
  • rt-n12hp_firmware
  • rt-ac3200
  • rt-n12hp
  • rt-ac55u_firmware
  • rt-n66u
  • rt-n12hp_b1_firmware
  • rt-n300
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer