CVE-2023-41345
- EPSS 1.16%
- Veröffentlicht 03.11.2023 05:15:29
- Zuletzt bearbeitet 21.11.2024 08:21:07
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attac...
CVE-2023-41346
- EPSS 0.6%
- Veröffentlicht 03.11.2023 05:15:29
- Zuletzt bearbeitet 21.11.2024 08:21:07
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack ...
CVE-2023-41347
- EPSS 0.6%
- Veröffentlicht 03.11.2023 05:15:29
- Zuletzt bearbeitet 21.11.2024 08:21:07
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to...
CVE-2023-41348
- EPSS 1.16%
- Veröffentlicht 03.11.2023 05:15:29
- Zuletzt bearbeitet 21.11.2024 08:21:07
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection a...
CVE-2023-39780
- EPSS 70.19%
- Veröffentlicht 11.09.2023 19:15:43
- Zuletzt bearbeitet 03.06.2025 20:59:05
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-r...
CVE-2023-39238
- EPSS 3.38%
- Veröffentlicht 07.09.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:58
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnera...
CVE-2023-39239
- EPSS 0.85%
- Veröffentlicht 07.09.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:58
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can explo...
CVE-2023-39240
- EPSS 0.85%
- Veröffentlicht 07.09.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:58
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privil...
CVE-2022-26376
- EPSS 0.65%
- Veröffentlicht 05.08.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 06:53:52
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a netw...
- EPSS 0.52%
- Veröffentlicht 05.07.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:39
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stor...