Vulnerability Name:

CVE-2017-11345 (CCN-128749)

Assigned:2017-07-14
Published:2017-07-14
Updated:2017-12-20
Summary:Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-11345

Source: CCN
Type: oss-sec Mailing List, Fri, 14 Jul 2017 11:23:56 +0800
Re: Re: Asus wireless routers Global buffer overflow and Stack buffer overflow in networkmap

Source: MISC
Type: Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2017/07/14/3

Source: CONFIRM
Type: UNKNOWN
https://asuswrt.lostrealm.ca/changelog

Source: XF
Type: UNKNOWN
asus-cve201711345-bo(128749)

Source: CCN
Type: ASUS Web site
ASUS devices

Vulnerable Configuration:Configuration 1:
  • cpe:/o:asuswrt-merlin_project:rt-ac5300_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac5300:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:asuswrt-merlin_project:rt_ac1900p_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt_ac1900p_:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:asuswrt-merlin_project:rt-ac68u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac68u:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:asuswrt-merlin_project:rt-ac68p_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac68p:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:asuswrt-merlin_project:rt-ac88u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac88u:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:asuswrt-merlin_project:rt-ac66u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac66u:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:asuswrt-merlin_project:rt-ac66u_b1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac66u_b1:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:asuswrt-merlin_project:rt-ac58u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7485)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac58u:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:asuswrt-merlin_project:rt-ac56u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac56u:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:asuswrt-merlin_project:rt-ac55u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac55u:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:asuswrt-merlin_project:rt-ac52u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.4180)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac52u:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:asuswrt-merlin_project:rt-ac51u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac51u:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:asuswrt-merlin_project:rt-n18u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n18u:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:asuswrt-merlin_project:rt-n66u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n66u:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:asuswrt-merlin_project:rt-n56u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.378.7177)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n56u:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:asuswrt-merlin_project:rt-ac3200_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac3200:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:asuswrt-merlin_project:rt-ac3100_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac3100:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:asuswrt-merlin_project:rt_ac1200gu_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.5577)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt_ac1200gu:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:asuswrt-merlin_project:rt_ac1200g_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.3167)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt_ac1200g:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:asuswrt-merlin_project:rt-ac1200_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9880)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac1200:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:asuswrt-merlin_project:rt-ac53_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9883)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-ac53:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:asuswrt-merlin_project:rt-n12hp_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.2943)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n12hp:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:asuswrt-merlin_project:rt-n12hp_b1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.3479)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n12hp_b1:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:asuswrt-merlin_project:rt-n12d1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n12d1:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:asuswrt-merlin_project:rt-n12+_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n12+:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:asuswrt-merlin_project:rt_n12+_pro_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9880)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt_n12+_pro:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:asuswrt-merlin_project:rt-n16_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n16:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:asuswrt-merlin_project:rt-n300_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)
  • AND
  • cpe:/h:asuswrt-merlin_project:rt-n300:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:asus:rt-n16:-:*:*:*:*:*:*:*
  • OR cpe:/h:asus:rt-n12_d1:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    asuswrt-merlin_project rt-ac5300 firmware *
    asuswrt-merlin_project rt-ac5300 -
    asuswrt-merlin_project rt ac1900p firmware *
    asuswrt-merlin_project rt ac1900p -
    asuswrt-merlin_project rt-ac68u firmware *
    asuswrt-merlin_project rt-ac68u -
    asuswrt-merlin_project rt-ac68p firmware *
    asuswrt-merlin_project rt-ac68p -
    asuswrt-merlin_project rt-ac88u firmware *
    asuswrt-merlin_project rt-ac88u -
    asuswrt-merlin_project rt-ac66u firmware *
    asuswrt-merlin_project rt-ac66u -
    asuswrt-merlin_project rt-ac66u b1 firmware *
    asuswrt-merlin_project rt-ac66u b1 -
    asuswrt-merlin_project rt-ac58u firmware *
    asuswrt-merlin_project rt-ac58u -
    asuswrt-merlin_project rt-ac56u firmware *
    asuswrt-merlin_project rt-ac56u -
    asuswrt-merlin_project rt-ac55u firmware *
    asuswrt-merlin_project rt-ac55u -
    asuswrt-merlin_project rt-ac52u firmware *
    asuswrt-merlin_project rt-ac52u -
    asuswrt-merlin_project rt-ac51u firmware *
    asuswrt-merlin_project rt-ac51u -
    asuswrt-merlin_project rt-n18u firmware *
    asuswrt-merlin_project rt-n18u -
    asuswrt-merlin_project rt-n66u firmware *
    asuswrt-merlin_project rt-n66u -
    asuswrt-merlin_project rt-n56u firmware *
    asuswrt-merlin_project rt-n56u -
    asuswrt-merlin_project rt-ac3200 firmware *
    asuswrt-merlin_project rt-ac3200 -
    asuswrt-merlin_project rt-ac3100 firmware *
    asuswrt-merlin_project rt-ac3100 -
    asuswrt-merlin_project rt ac1200gu firmware *
    asuswrt-merlin_project rt ac1200gu -
    asuswrt-merlin_project rt ac1200g firmware *
    asuswrt-merlin_project rt ac1200g -
    asuswrt-merlin_project rt-ac1200 firmware *
    asuswrt-merlin_project rt-ac1200 -
    asuswrt-merlin_project rt-ac53 firmware *
    asuswrt-merlin_project rt-ac53 -
    asuswrt-merlin_project rt-n12hp firmware *
    asuswrt-merlin_project rt-n12hp -
    asuswrt-merlin_project rt-n12hp b1 firmware *
    asuswrt-merlin_project rt-n12hp b1 -
    asuswrt-merlin_project rt-n12d1 firmware *
    asuswrt-merlin_project rt-n12d1 -
    asuswrt-merlin_project rt-n12+ firmware *
    asuswrt-merlin_project rt-n12+ -
    asuswrt-merlin_project rt n12+ pro firmware *
    asuswrt-merlin_project rt n12+ pro -
    asuswrt-merlin_project rt-n16 firmware *
    asuswrt-merlin_project rt-n16 -
    asuswrt-merlin_project rt-n300 firmware *
    asuswrt-merlin_project rt-n300 -
    asus rt-n16 -
    asus rt-n12 d1 -