CRITICAL · 9.1

CVE-2021-37315

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the...

Vulnerability Description

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AsusRt-Ac68U Firmware< 3.0.0.4.386.41634
AsusRt-Ac68U-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-37315?

CVE-2021-37315 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the...

How severe is CVE-2021-37315?

CVE-2021-37315 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-37315?

Check the references section above for vendor advisories and patch information. Affected products include: Asus Rt-Ac68U Firmware, Asus Rt-Ac68U.