ASUS Vulnerabilities and Affected Products
Vulnerabilities associated with RT-AC86U.
Products
Clear product- BMC firmware for ASMB8-iKVM18 vulnerabilities
- BMC firmware for Z10PE-D16 WS18 vulnerabilities
- BMC firmware for Z10PR-D1618 vulnerabilities
- BMC firmware for ASMB9-iKVM17 vulnerabilities
- BMC firmware for E700 G417 vulnerabilities
- BMC firmware for ESC4000 DHD G417 vulnerabilities
- BMC firmware for ESC4000 G417 vulnerabilities
- BMC firmware for ESC4000 G4X17 vulnerabilities
- BMC firmware for ESC8000 G417 vulnerabilities
- BMC firmware for ESC8000 G4/10G17 vulnerabilities
- BMC firmware for KNPA-U1617 vulnerabilities
- BMC firmware for Pro E800 G417 vulnerabilities
- BMC firmware for RS100-E10-PI217 vulnerabilities
- BMC firmware for RS300-E10-PS417 vulnerabilities
- BMC firmware for RS300-E10-RS417 vulnerabilities
- BMC firmware for RS500-E9-PS417 vulnerabilities
- BMC firmware for RS500-E9-RS417 vulnerabilities
- BMC firmware for RS500-E9-RS4-U17 vulnerabilities
- BMC firmware for RS500A-E10-PS417 vulnerabilities
- BMC firmware for RS500A-E10-RS417 vulnerabilities
- BMC firmware for RS500A-E9 RS417 vulnerabilities
- BMC firmware for RS500A-E9-PS417 vulnerabilities
- BMC firmware for RS500A-E9-RS417 vulnerabilities
- BMC firmware for RS520-E9-RS12-E17 vulnerabilities
- BMC firmware for RS520-E9-RS817 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3080CRITICAL | ASUS Router - Improper AuthenticationCertain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | CVSS9.8v3.1 | EPSS43.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-3079HIGH | ASUS Router - Stack-based Buffer OverflowCertain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device. CWE-121Jun 14, 2024 | CVSS7.2v3.1 | EPSS0.826% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0401HIGH | ASUS OVPN RCEASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000. CWE-78May 20, 2024 | CVSS7.2v3.1 | EPSS0.735% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39239HIGH | ASUS RT-AX55、RT-AX56U_V2、RT-AC86U - Format String - 2It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. CWE-134Sep 7, 2023 | CVSS7.2v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39237HIGH | ASUS RT-AC86U - Command injection vulnerability - 5ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. CWE-78Sep 7, 2023 | CVSS8.8v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39236HIGH | ASUS RT-AC86U - Command injection vulnerability - 4ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. CWE-78Sep 7, 2023 | CVSS8.8v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38033HIGH | ASUS RT-AC86U - Command injection vulnerability - 3ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. CWE-78Sep 7, 2023 | CVSS8.8v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38032HIGH | ASUS RT-AC86U - Command injection vulnerability - 2ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. CWE-78Sep 7, 2023 | CVSS8.8v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38031HIGH | ASUS RT-AC86U - Command injection vulnerability - 1ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. CWE-78Sep 7, 2023 | CVSS8.8v3.1 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35087CRITICAL | ASUS RT-AX56U V2 & RT-AC86U - Format String - 2It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_5… CWE-134Jul 21, 2023 | CVSS9.8v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35086HIGH | ASUS RT-AX56U V2 & RT-AC86U - Format String -1It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529. CWE-134Jul 21, 2023 | CVSS7.2v3.1 | EPSS38.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28702HIGH | ASUS RT-AC86U - Command InjectionASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service. CWE-78Jun 2, 2023 | CVSS8.8v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28703HIGH | ASUS RT-AC86U - Buffer OverflowASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service. | CVSS7.2v3.1 | EPSS0.886% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25597HIGH | ASUS RT-AC86U - Command InjectionASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service. CWE-78Apr 7, 2022 | CVSS8.8v3.1 | EPSS0.863% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25596HIGH | ASUS RT-AC86U - Heap-based buffer overflowASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service. CWE-787Apr 7, 2022 | CVSS8.8v3.1 | EPSS0.568% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25595MEDIUM | ASUS RT-AC86U - Improper Input ValidationASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt. CWE-20Apr 7, 2022 | CVSS6.5v3.1 | EPSS0.395% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |