CVE Feed

    Dashboard / CVE / CVE-2017-12754

    CVE-2017-12754

    Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by sending a crafted http GET request packet that includes a long delete_offline_client parameter in the url.

    Published:Aug 9, 2017
    Last Modified:Apr 20, 2025
    EPS:Aug 9, 2017
    EPSS Score:0.10008
    CVSS Score:8.8

    Affected Products

    Vendor
    Asuswrt-merlin
    Product
    Asuswrt-merlin
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac1200
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac3100
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac3200
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac51u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac52u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac53
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac5300
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac55u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac56u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac58u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac66u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac66u B1
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac68p
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac68u
    Vendor
    Asuswrt-merlin
    Product
    Rt-ac88u
    Vendor
    Asuswrt-merlin
    Product
    Rt-n12\+
    Vendor
    Asuswrt-merlin
    Product
    Rt-n12d1
    Vendor
    Asuswrt-merlin
    Product
    Rt-n12hp
    Vendor
    Asuswrt-merlin
    Product
    Rt-n12hp B1
    Vendor
    Asuswrt-merlin
    Product
    Rt-n16
    Vendor
    Asuswrt-merlin
    Product
    Rt-n18u
    Vendor
    Asuswrt-merlin
    Product
    Rt-n300
    Vendor
    Asuswrt-merlin
    Product
    Rt-n56u
    Vendor
    Asuswrt-merlin
    Product
    Rt-n66u
    Vendor
    Asuswrt-merlin
    Product
    Rt Ac1200g
    Vendor
    Asuswrt-merlin
    Product
    Rt Ac1200gu
    Vendor
    Asuswrt-merlin
    Product
    Rt Ac1900p
    Vendor
    Asuswrt-merlin
    Product
    Rt N12\+ Pro

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High