peter bassill · operator
$ cve CVE-2013-6343 JSON

CVE-2013-6343 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 7.8% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS7.82% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2014-01-22
Last modified2026-06-17

Affected (6)

VendorProduct
asusrt-ac66u
asusrt-ac66u firmware
asusrt-n56u
asusrt-n56u firmware
asustm-ac1900
asustm-ac1900 firmware

Public exploits

SourceTitleDate
exploit-dbASUS RT-N56U - Remote Buffer Overflow (ROP)2014-01-19

References

→ the Explorer  ·  watch your stack  ·  NVD