7.2
CVE-2023-39238
- EPSS 3.38%
- Published 07.09.2023 08:15:07
- Last modified 21.11.2024 08:14:58
- Source twcert@cert.org.tw
- Teams watchlist Login
- Open Login
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Data is provided by the National Vulnerability Database (NVD)
Asus ≫ Rt-ax55 Firmware Version3.0.0.4.386_50460
Asus ≫ Rt-ax56u V2 Firmware Version3.0.0.4.386_50460
Asus ≫ Rt-ac86u Firmware Version3.0.0.4_386_51529
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.38% | 0.869 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
twcert@cert.org.tw | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.