9.8
CRITICAL
CVE-2024-3080
ASUS Router Authentication Bypass Vulnerability
Description

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

INFO

Published Date :

June 14, 2024, 3:15 a.m.

Last Modified :

Nov. 21, 2024, 9:28 a.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

3.9
Affected Products

The following products are affected by CVE-2024-3080 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Asus rt-ac86u_firmware
2 Asus rt-ax88u_firmware
3 Asus rt-ax58u_firmware
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-3080.

URL Resource
https://www.twcert.org.tw/en/cp-139-7860-760b1-2.html
https://www.twcert.org.tw/tw/cp-132-7859-0e104-1.html
https://www.twcert.org.tw/en/cp-139-7860-760b1-2.html
https://www.twcert.org.tw/tw/cp-132-7859-0e104-1.html

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-3080 vulnerability anywhere in the article.

  • The Hacker News
Cloudflare Thwarts Largest-Ever 3.8 Tbps DDoS Attack Targeting Global Sectors

Cloudflare has disclosed that it mitigated a record-breaking distributed denial-of-service (DDoS) attack that peaked at 3.8 terabits per second (Tbps) and lasted 65 seconds. The web infrastructure and ... Read more

Published Date: Oct 04, 2024 (2 months, 2 weeks ago)
  • TheCyberThrone
Cloudflare mitigated record 3.8Tbps DDoS attack

Cloudflare has been reported that it has mitigated over 100 hyper-volumetric L3/4 DDoS attacks, with many exceeding 2 billion Pps and 3 Tbps. The largest DDoS attack peaked at 3.8 Tbps, which is the h ... Read more

Published Date: Oct 03, 2024 (2 months, 3 weeks ago)
  • Cybersecurity News
Multiple Vulnerabilities Discovered in PHP, Prompting Urgent Security Updates

The PHP project has recently released a security advisory, addressing several vulnerabilities affecting various versions of PHP. These vulnerabilities range from potential log tampering to arbitrary f ... Read more

Published Date: Sep 30, 2024 (2 months, 3 weeks ago)
  • Cybersecurity News
GreyNoise Intelligence Uncovers New Internet Noise Storm with Potential China Link and Cryptic “LOVE” Message

GreyNoise Intelligence has recently released findings regarding a new and increasingly complex wave of “Noise Storms” – massive, enigmatic surges of fake traffic that have baffled experts since 2020. ... Read more

Published Date: Sep 23, 2024 (3 months ago)
  • Cybersecurity News
BadIIS Malware : 35+ IIS Servers Compromised in DragonRank Campaign

A recent report from Cisco Talos has exposed a new threat actor named DragonRank, a Chinese-speaking group specializing in SEO manipulation and cyberattacks. This group operates by exploiting vulnerab ... Read more

Published Date: Sep 15, 2024 (3 months, 1 week ago)
  • Cybersecurity News
CVE-2024-8522 (CVSS 10): LearnPress SQLi Flaw Leaves 90K+ WordPress Sites at Risk

A critical SQL injection vulnerability has been discovered in LearnPress, a popular WordPress plugin used to create and manage online courses. The flaw, tracked as CVE-2024-8522, carries a maximum CVS ... Read more

Published Date: Sep 12, 2024 (3 months, 1 week ago)
  • Cybersecurity News
ECDSA Vulnerability in YubiKey: What You Need to Know

OLYMPUS DIGITAL CAMERAIn a recent security advisory, Yubico disclosed a moderate vulnerability (CVE-2024-45678) affecting several of its hardware security devices, including the widely-used YubiKey 5 ... Read more

Published Date: Sep 05, 2024 (3 months, 2 weeks ago)
  • Cybersecurity News
D-Link Won’t Fix 4 RCE Vulnerabilities in DIR-846W Router

Four severe security flaws have been found in the D-Link DIR-846W router, leaving users potentially exposed to remote attacks even after the device has reached its end-of-life.Security researchers hav ... Read more

Published Date: Sep 03, 2024 (3 months, 3 weeks ago)

The following table lists the changes that have been made to the CVE-2024-3080 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://www.twcert.org.tw/en/cp-139-7860-760b1-2.html
    Added Reference https://www.twcert.org.tw/tw/cp-132-7859-0e104-1.html
  • CVE Received by [email protected]

    Jun. 14, 2024

    Action Type Old Value New Value
    Added Description Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
    Added Reference TWCERT/CC https://www.twcert.org.tw/tw/cp-132-7859-0e104-1.html [No types assigned]
    Added Reference TWCERT/CC https://www.twcert.org.tw/en/cp-139-7860-760b1-2.html [No types assigned]
    Added CWE TWCERT/CC CWE-287
    Added CVSS V3.1 TWCERT/CC AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-3080 is associated with the following CWEs:

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability