9.8
CVE-2022-26674
- EPSS 4.55%
- Veröffentlicht 22.04.2022 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:18
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asus ≫ Rt-ax88u Firmware Version < 3.0.0.4.386.46065
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.55% | 0.887 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| twcert@cert.org.tw | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.