Description Preview
Overview
The XXE vulnerabilities in ASUS DSL routers' AiCloud feature present a significant security risk as they allow authenticated attackers to access files that should be restricted. When exploited, an attacker can craft special XML requests containing malicious DTD definitions that instruct the XML parser to access local files on the router's file system. This can lead to the disclosure of sensitive configuration files, credentials, or other critical information stored on the device.
The vulnerability specifically affects the processing of XML data in two different request types:
- UPDATEACCOUNT requests in the AiCloud feature
- PROPFIND requests in the AiCloud feature
Both vulnerabilities require authentication to exploit, which somewhat limits the attack surface, but still represents a serious security concern for deployed devices.
Remediation
To address these vulnerabilities, users should take the following actions:
-
Update router firmware immediately to the latest version provided by ASUS. The manufacturer has released patches to address these vulnerabilities.
-
Visit the ASUS support website (specifically the HelpDesk_BIOS section for your router model) to download and install the latest firmware.
-
If updates are not immediately available for your specific model, consider implementing these temporary mitigations:
- Disable the AiCloud feature if not actively used
- Ensure strong authentication credentials are set for router access
- Limit administrative access to trusted IP addresses only
- Monitor router logs for suspicious activities
-
After updating, verify that the update was successful by checking the current firmware version in the router's administration interface.
References
-
ASUS DSL-N14U-B1 firmware updates and advisories: https://www.asus.com/Networking/DSL-N14U-B1/HelpDesk_BIOS/
-
Security Artwork vulnerability analysis (Note: This link may no longer be active): https://www.securityartwork.es/2018/01/25/some-vulnerability-in-asus-routers/
-
CWE-611: Improper Restriction of XML External Entity Reference: https://cwe.mitre.org/data/definitions/611.html
-
ASUS Support Center for checking firmware updates for all affected models: https://www.asus.com/support/
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade