CVE-2014-2925: ASUS Rt-AC68U
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi.
Affected products
- ASUS Rt-AC68U
- ASUS Rt-AC68U Firmware: up to and including 3.0.0.4.374_4983; version 3.0.0.4.374.4755 only; version 3.0.0.4.374_4887 only
- T-Mobile TM-AC1900: version 3.0.0.4.376_3169 only
Published 2014-04-22. Last modified 2026-06-17.