CVE-2017-12754
Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by sending a crafted http GET request packet that includes a long delete_offline_client parameter in the url.
Published:Aug 9, 2017
Last Modified:Apr 20, 2025
EPS:Aug 9, 2017
EPSS Score:0.10008
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Asuswrt-merlin
Product
Asuswrt-merlin
Asuswrt-merlin
Asuswrt-merlin
Vendor
Asuswrt-merlin
Product
Rt-ac1200
Asuswrt-merlin
Rt-ac1200
Vendor
Asuswrt-merlin
Product
Rt-ac3100
Asuswrt-merlin
Rt-ac3100
Vendor
Asuswrt-merlin
Product
Rt-ac3200
Asuswrt-merlin
Rt-ac3200
Vendor
Asuswrt-merlin
Product
Rt-ac51u
Asuswrt-merlin
Rt-ac51u
Vendor
Asuswrt-merlin
Product
Rt-ac52u
Asuswrt-merlin
Rt-ac52u
Vendor
Asuswrt-merlin
Product
Rt-ac53
Asuswrt-merlin
Rt-ac53
Vendor
Asuswrt-merlin
Product
Rt-ac5300
Asuswrt-merlin
Rt-ac5300
Vendor
Asuswrt-merlin
Product
Rt-ac55u
Asuswrt-merlin
Rt-ac55u
Vendor
Asuswrt-merlin
Product
Rt-ac56u
Asuswrt-merlin
Rt-ac56u
Vendor
Asuswrt-merlin
Product
Rt-ac58u
Asuswrt-merlin
Rt-ac58u
Vendor
Asuswrt-merlin
Product
Rt-ac66u
Asuswrt-merlin
Rt-ac66u
Vendor
Asuswrt-merlin
Product
Rt-ac66u B1
Asuswrt-merlin
Rt-ac66u B1
Vendor
Asuswrt-merlin
Product
Rt-ac68p
Asuswrt-merlin
Rt-ac68p
Vendor
Asuswrt-merlin
Product
Rt-ac68u
Asuswrt-merlin
Rt-ac68u
Vendor
Asuswrt-merlin
Product
Rt-ac88u
Asuswrt-merlin
Rt-ac88u
Vendor
Asuswrt-merlin
Product
Rt-n12\+
Asuswrt-merlin
Rt-n12\+
Vendor
Asuswrt-merlin
Product
Rt-n12d1
Asuswrt-merlin
Rt-n12d1
Vendor
Asuswrt-merlin
Product
Rt-n12hp
Asuswrt-merlin
Rt-n12hp
Vendor
Asuswrt-merlin
Product
Rt-n12hp B1
Asuswrt-merlin
Rt-n12hp B1
Vendor
Asuswrt-merlin
Product
Rt-n16
Asuswrt-merlin
Rt-n16
Vendor
Asuswrt-merlin
Product
Rt-n18u
Asuswrt-merlin
Rt-n18u
Vendor
Asuswrt-merlin
Product
Rt-n300
Asuswrt-merlin
Rt-n300
Vendor
Asuswrt-merlin
Product
Rt-n56u
Asuswrt-merlin
Rt-n56u
Vendor
Asuswrt-merlin
Product
Rt-n66u
Asuswrt-merlin
Rt-n66u
Vendor
Asuswrt-merlin
Product
Rt Ac1200g
Asuswrt-merlin
Rt Ac1200g
Vendor
Asuswrt-merlin
Product
Rt Ac1200gu
Asuswrt-merlin
Rt Ac1200gu
Vendor
Asuswrt-merlin
Product
Rt Ac1900p
Asuswrt-merlin
Rt Ac1900p
Vendor
Asuswrt-merlin
Product
Rt N12\+ Pro
Asuswrt-merlin
Rt N12\+ Pro
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
