← Vulnerability feed

Vulnerability record · CVE-2021-37317 · published 3 February 2023

CVE-2021-37317: Asus rt-ac68u firmware path traversal vulnerability

Asus · Rt Ac68u Firmware

Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

9.1 CVSS 3.1 Critical EPSS 1.5% · top 26.2% CWE-22 · Path traversal
9.1CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://robertchen.cc/blog/2021/03/31/asus-rce ExploitMitigationThird Party Advisory
https://robertchen.cc/blog/2021/03/31/asus-rce ExploitMitigationThird Party Advisory

Track CVE-2021-37317 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45756Asus rt-ac68u firmware classic buffer overflow vulnerabilityAsus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.EPSS 1.2%9.8CVE-2018-9285Asus rt-ac66u firmware os command injection vulnerabilityMain_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…EPSS 3.6%9.1CVE-2021-37315Asus rt-ac68u firmware vulnerabilityIncorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to w…EPSS 1.1%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.5CVE-2013-5948T-mobile tm-ac1900 os command injection vulnerabilityThe Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows re…EPSS 9.5%7.5CVE-2021-37316Asus rt-ac68u firmware sql injection vulnerabilitySQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive…EPSS 1.0%7.5CVE-2021-45757Asus rt-ac68u firmware classic buffer overflow vulnerabilityASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).EPSS 1.1%7.5CVE-2021-3128Asus zenwifi ax \(xt8\) firmware vulnerabilityIn ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2021-37317), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.