Description
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.
Published: 2018-01-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-6196 Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.
History

No history.

Subscriptions

Asus Dsl-ac51 Dsl-ac51 Firmware Dsl-ac52u Dsl-ac52u Firmware Dsl-ac55u Dsl-ac55u Firmware Dsl-ac56u Dsl-ac56u Firmware Dsl-ac750 Dsl-ac750 Firmware Dsl-n10 C1 Dsl-n10 C1 Firmware Dsl-n12e C1 Dsl-n12e C1 Firmware Dsl-n12u C1 Dsl-n12u C1 Firmware Dsl-n14u Dsl-n14u-b1 Dsl-n14u-b1 Firmware Dsl-n14u Firmware Dsl-n16 Dsl-n16 Firmware Dsl-n16u Dsl-n16u Firmware Dsl-n17u Dsl-n17u Firmware Dsl-n55u C1 Dsl-n55u C1 Firmware Dsl-n55u D1 Dsl-n55u D1 Firmware Dsl-n66u Dsl-n66u Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T19:34:39.910Z

Reserved: 2017-09-22T00:00:00.000Z

Link: CVE-2017-14699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-29T16:29:00.357

Modified: 2024-11-21T03:13:20.940

Link: CVE-2017-14699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses