본문 바로가기
보안

ASUS RT-AX58U Firmware version 3.0.0.4.388.22237

by 촐초리 2023. 1. 12.
반응형
ASUS RT-AX58U 새로운 펌웨어가 나왔다
Firmware version 3.0.0.4.388.22237

1. Supported WireGuard VPN server and client.
2. Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.
3. Supported new devices connection notification.
4. Supported connection diagnostic on the ASUS router app.
5. Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.
6. Upgraded parental control and added reward, new scheduler for flexible setting
7. Fixed USB icon issue in port status.
8. Fixed HTTP response splitting vulnerability. Thanks to Efstratios Chatzoglou, University of the Aegean.
9. Fixed status page HTML vulnerability. Thanks to David Ward.
10. Fixed CVE-2018-1160. Thanks to Steven Sroba.
11. Fixed cfg_server security issue.

RT-AX82U 라우터에는  CVE-2022-35401 취약점이 있다고 한다

HTTP 요청을 악용하여 인증을 바이패스 하는 것이 가능하다

즉 웹 접속을 통해 관리자 권한을 얻을수 있다는 것이다

 

이 기기를 가진 이들은 반드시 새버전으로 업데이트 

https://www.securityweek.com/severe-vulnerabilities-allow-hacking-asus-gaming-router

 

Severe Vulnerabilities Allow Hacking of Asus Gaming Router | SecurityWeek.Com

Cisco’s Talos security researchers have published technical information on three severe vulnerabilities impacting Asus RT-AX82U routers. A Wi-Fi 6 gaming router, the RT-AX82U can be configured via an HTTP server that is running on the local network, but

www.securityweek.com

 

반응형