ASUS Vulnerabilities and Affected Products
Vulnerabilities associated with RT-AX88U.
Products
Clear product- BMC firmware for ASMB8-iKVM18 vulnerabilities
- BMC firmware for Z10PE-D16 WS18 vulnerabilities
- BMC firmware for Z10PR-D1618 vulnerabilities
- BMC firmware for ASMB9-iKVM17 vulnerabilities
- BMC firmware for E700 G417 vulnerabilities
- BMC firmware for ESC4000 DHD G417 vulnerabilities
- BMC firmware for ESC4000 G417 vulnerabilities
- BMC firmware for ESC4000 G4X17 vulnerabilities
- BMC firmware for ESC8000 G417 vulnerabilities
- BMC firmware for ESC8000 G4/10G17 vulnerabilities
- BMC firmware for KNPA-U1617 vulnerabilities
- BMC firmware for Pro E800 G417 vulnerabilities
- BMC firmware for RS100-E10-PI217 vulnerabilities
- BMC firmware for RS300-E10-PS417 vulnerabilities
- BMC firmware for RS300-E10-RS417 vulnerabilities
- BMC firmware for RS500-E9-PS417 vulnerabilities
- BMC firmware for RS500-E9-RS417 vulnerabilities
- BMC firmware for RS500-E9-RS4-U17 vulnerabilities
- BMC firmware for RS500A-E10-PS417 vulnerabilities
- BMC firmware for RS500A-E10-RS417 vulnerabilities
- BMC firmware for RS500A-E9 RS417 vulnerabilities
- BMC firmware for RS500A-E9-PS417 vulnerabilities
- BMC firmware for RS500A-E9-RS417 vulnerabilities
- BMC firmware for RS520-E9-RS12-E17 vulnerabilities
- BMC firmware for RS520-E9-RS817 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3080CRITICAL | ASUS Router - Improper AuthenticationCertain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | CVSS9.8v3.1 | EPSS43.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-3079HIGH | ASUS Router - Stack-based Buffer OverflowCertain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device. CWE-121Jun 14, 2024 | CVSS7.2v3.1 | EPSS0.826% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0401HIGH | ASUS OVPN RCEASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000. CWE-78May 20, 2024 | CVSS7.2v3.1 | EPSS0.735% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41349HIGH | ASUS RT-AX88U - externally-controlled format stringASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service. CWE-134Sep 18, 2023 | CVSS8.8v3.1 | EPSS0.645% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-34360HIGH | ASUS RT-AX88U - Stored XSSA stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior. After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code. CWE-79Jul 31, 2023 | CVSS8.2v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-34359HIGH | ASUS RT-AX88U - Out-of-bounds Read - 2ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition. CWE-125Jul 31, 2023 | CVSS7.5v3.1 | EPSS0.815% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-34358HIGH | ASUS RT-AX88U - Out-of-bounds Read - 1ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition. CWE-125Jul 31, 2023 | CVSS7.5v3.1 | EPSS0.815% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26674CRITICAL | ASUS RT-AX88U - Format StringASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service. CWE-134Apr 22, 2022 | CVSS9.8v3.1 | EPSS2.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26673MEDIUM | ASUS RT-AX88U - Stored XSSASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks. CWE-79Apr 22, 2022 | CVSS5.4v3.1 | EPSS0.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |