CVE-2017-14699

moderate-risk
Published 2018-01-29

Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read arbitrary files via a crafted DTD in (1) an UPDATEACCOUNT or (2) a PROPFIND request.

Do I need to act?

-
0.32% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10 Medium
NETWORK / LOW complexity

Affected Products (16)

Dsl-Ac51 Firmware
Dsl-Ac52U Firmware
Dsl-Ac55U Firmware
Dsl-N55U C1 Firmware
Dsl-N55U D1 Firmware
Dsl-Ac56U Firmware
Dsl-N10 C1 Firmware
Dsl-N12U C1 Firmware
Dsl-N12E C1 Firmware
Dsl-N14U Firmware
Dsl-N14U-B1 Firmware
Dsl-N16 Firmware
Dsl-N16U Firmware
Dsl-N17U Firmware
Dsl-N66U Firmware
Dsl-Ac750 Firmware

Affected Vendors

43
/ 100
moderate-risk
Severity 24/34 · High
Exploitability 1/34 · Minimal
Exposure 18/34 · Moderate