HIGH · 10.0

CVE-2013-6343

Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_fl...

Vulnerability Description

Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AsusTm-Ac1900 Firmware3.0.0.4..374_979
AsusTm-Ac1900-
AsusRt-N56U Firmware3.0.0.4..374_979
AsusRt-N56U-
AsusRt-Ac66U Firmware3.0.0.4..374_979
AsusRt-Ac66U-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6343?

CVE-2013-6343 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_fl...

How severe is CVE-2013-6343?

CVE-2013-6343 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-6343?

Check the references section above for vendor advisories and patch information. Affected products include: Asus Tm-Ac1900 Firmware, Asus Tm-Ac1900, Asus Rt-N56U Firmware, Asus Rt-N56U, Asus Rt-Ac66U Firmware.