Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2023-28702

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
Attacker Value
Unknown

CVE-2023-28703

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.
Attacker Value
Unknown

CVE-2023-39240

Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-39239

Disclosure Date: September 07, 2023 (last updated March 27, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-39238

Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-39237

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-39236

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38033

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38032

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Attacker Value
Unknown

CVE-2023-38031

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.