← Vulnerability feed

Vulnerability record · CVE-2014-2718 · published 4 November 2014

CVE-2014-2718: T-mobile tm-ac1900 insufficient verification of data authenticity vulnerability

T Mobile · Tm Ac1900

ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

7.1 CVSS 2.0 High EPSS 1.1% · top 35.6% CWE-345 · Insufficient verification of data authenticity
7.1CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

AV:N/AC:M/Au:N/C:N/I:C/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2718 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-9583ASUS WRT infosvr Missing MAC Check Allows Command ExecutionThe infosvr component in ASUS WRT firmware fails to validate the MAC address on incoming requests, so authentication can be bypassed. A remote attack…EPSS 80%analysed8.5CVE-2013-5948T-mobile tm-ac1900 os command injection vulnerabilityThe Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows re…EPSS 9.5%7.2CVE-2013-1813Redhat enterprise linux permissions and access controls vulnerabilityutil-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…EPSS 0.62%6.8CVE-2011-2716T-mobile tm-ac1900 improper input validation vulnerabilityThe DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_N…EPSS 1.8%6.3CVE-2014-2719Asus rt-ac66u firmware information exposure vulnerabilityAdvanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remo…EPSS 1.1%4.3CVE-2014-2925T-mobile tm-ac1900 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.3…EPSS 1.2%7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed9.8CVE-2022-26871Trend Micro Apex Central unauthenticated arbitrary file uploadTrend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2014-2718), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.