Home

Description

An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

PUBLISHED Reserved 2024-12-31 | Published 2025-01-02 | Updated 2025-01-06 | Assigner ASUS




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-912: Hidden Functionality

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

Default status
unaffected

3.0.0.4_382 series (custom)
affected

3.0.0.4_386 series (custom)
affected

3.0.0.4_388 series (custom)
affected

3.0.0.6_102 series (custom)
affected

References

www.asus.com/content/asus-product-security-advisory/

cve.org (CVE-2024-13062)

nvd.nist.gov (CVE-2024-13062)

Download JSON