An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/vu/JVNVU96079387/ | Third Party Advisory |
| https://www.asus.com/event/network/EOL-product/ | Product |
| https://www.asus.com/support/ | Not Applicable |
| https://jvn.jp/en/vu/JVNVU96079387/ | Third Party Advisory |
| https://www.asus.com/event/network/EOL-product/ | Product |
| https://www.asus.com/support/ | Not Applicable |
Configurations
Configuration 1 (hide)
| AND |
|
History
21 Nov 2024, 08:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jvn.jp/en/vu/JVNVU96079387/ - Third Party Advisory | |
| References | () https://www.asus.com/event/network/EOL-product/ - Product | |
| References | () https://www.asus.com/support/ - Not Applicable |
27 Aug 2024, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
03 Jul 2024, 01:42
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 |
21 Nov 2023, 19:44
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-11-15 02:15
Updated : 2024-11-21 08:30
NVD link : CVE-2023-47678
Mitre link : CVE-2023-47678
CVE.ORG link : CVE-2023-47678
JSON object : View
Products Affected
asus
- rt-ac87u
- rt-ac87u_firmware
CWE
