Description
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6196 | Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request. |
References
History
No history.
Subscriptions
Asus
Subscribe
Dsl-ac51
Subscribe
Dsl-ac51 Firmware
Subscribe
Dsl-ac52u
Subscribe
Dsl-ac52u Firmware
Subscribe
Dsl-ac55u
Subscribe
Dsl-ac55u Firmware
Subscribe
Dsl-ac56u
Subscribe
Dsl-ac56u Firmware
Subscribe
Dsl-ac750
Subscribe
Dsl-ac750 Firmware
Subscribe
Dsl-n10 C1
Subscribe
Dsl-n10 C1 Firmware
Subscribe
Dsl-n12e C1
Subscribe
Dsl-n12e C1 Firmware
Subscribe
Dsl-n12u C1
Subscribe
Dsl-n12u C1 Firmware
Subscribe
Dsl-n14u
Subscribe
Dsl-n14u-b1
Subscribe
Dsl-n14u-b1 Firmware
Subscribe
Dsl-n14u Firmware
Subscribe
Dsl-n16
Subscribe
Dsl-n16 Firmware
Subscribe
Dsl-n16u
Subscribe
Dsl-n16u Firmware
Subscribe
Dsl-n17u
Subscribe
Dsl-n17u Firmware
Subscribe
Dsl-n55u C1
Subscribe
Dsl-n55u C1 Firmware
Subscribe
Dsl-n55u D1
Subscribe
Dsl-n55u D1 Firmware
Subscribe
Dsl-n66u
Subscribe
Dsl-n66u Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:34:39.910Z
Reserved: 2017-09-22T00:00:00.000Z
Link: CVE-2017-14699
No data.
Status : Modified
Published: 2018-01-29T16:29:00.357
Modified: 2024-11-21T03:13:20.940
Link: CVE-2017-14699
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD