7.2

CVE-2023-39238

It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

Data is provided by the National Vulnerability Database (NVD)
AsusRt-ax55 Firmware Version3.0.0.4.386_50460
   AsusRt-ax55 Version-
AsusRt-ax56u V2 Firmware Version3.0.0.4.386_50460
   AsusRt-ax56u V2 Version-
AsusRt-ac86u Firmware Version3.0.0.4_386_51529
   AsusRt-ac86u Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.38% 0.869
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
twcert@cert.org.tw 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.