CVE-2020-36109

CRITICAL

Asus Rt-ax86u Firmware < 9.0.0.4_386 - Buffer Overflow

Title source: rule

Description

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

Exploits (2)

nomisec WORKING POC 17 stars
by sunn1day · poc
https://github.com/sunn1day/CVE-2020-36109-POC
nomisec SUSPICIOUS 2 stars
by tin-z · poc
https://github.com/tin-z/CVE-2020-36109-POC

Scores

CVSS v3 9.8
EPSS 0.1294
EPSS Percentile 94.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (1)
asus/rt-ax86u_firmware < 9.0.0.4_386
Published Feb 01, 2021
Tracked Since Feb 18, 2026