The Internet is an indispensable thing for modern people, just like sunlight, air and water, they cannot survive without it. Almost all work and life must be carried out in an online environment. Therefore, network security is much more important in this era than in the past. Hardware manufacturer Asus recently rolled out an update that fixes several critical vulnerabilities that could allow hackers to remotely control a range of router models without user authentication or interaction.

High-severity vulnerabilities affect multiple Asus routers, please repair or replace them as soon as possible
The most serious vulnerability, CVE-2024-3080, is a flaw that can bypass authentication, allowing remote attackers to log into the device without authentication, according toTaiwan Computer Network Crisis Management and Coordination Center (TWCERT/CC)It received a hazard severity score of 9.8 out of 10.

The second vulnerability, CVE-2024-3079, affects the same router model. It results from a buffer overflow flaw that allows remote hackers who have gained administrative access to an affected router to execute commands. The third vulnerability TWCERT/CC warns affects various Asus routers and is tracked as CVE-2024-3912, which could allow remote hackers to execute commands without requiring user authentication. The severity of this vulnerability is 9.8, and the affected models are as follows:
Security updates have been rolling out since January, and the security fixes for these models are available through the link above. CVE-2024-3912 will also affect router models that Asus no longer supports. TWCERT/CC recommends users to replace them with new models as soon as possible, including:
- DSL-N10_C1
- DSL-N10_D1
- DSL-N10P_C1
- DSL-N12E_C1
- DSL-N16P
- DSL-N16U
- DSL-AC52
- DSL-AC55

Asus recommends that all router users regularly check their devices to ensure they are running the latest available firmware.该公司还建议用户在无线网路何路由器管理页面设定独立且强化难度的密码。 Asus also recommends that users disable any services that can be accessed from the network, including remote access from WAN, port forwarding, DDNS, VPN servers, DMZ and port triggers. Meanwhile, Asus offersFAQ pageFor consumer inquiries.
Source: KOCPC Chinese