Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2023-28702
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
1
Attacker Value
Unknown
CVE-2023-28703
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.
1
Attacker Value
Unknown
CVE-2023-39240
Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2023-39239
Disclosure Date: September 07, 2023 (last updated March 27, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2023-39238
Disclosure Date: September 07, 2023 (last updated April 02, 2024)
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2023-39237
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
0
Attacker Value
Unknown
CVE-2023-39236
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
0
Attacker Value
Unknown
CVE-2023-38033
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
0
Attacker Value
Unknown
CVE-2023-38032
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
0
Attacker Value
Unknown
CVE-2023-38031
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
0