Description
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
Problem types
CWE-288: Authentication Bypass Using an Alternate Path or Channel
Product status
3.0.0.4_382 series
3.0.0.4_386 series
3.0.0.4_388 series
3.0.0.6_102 series
Credits
Nanyu Zhong of VARAS@IIE
NICTER Analysis Team of Cybersecurity Research Institute, National Institute of Information and Communications Technology
References
www.asus.com/content/asus-product-security-advisory/