CVE-2022-26674

CRITICAL

ASUS RT-AX88U - RCE

Title source: llm
STIX 2.1

Description

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.

Scores

CVSS v3 9.8
EPSS 0.0455
EPSS Percentile 89.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-134
Status published
Products (1)
asus/rt-ax88u_firmware < 3.0.0.4.386.46065
Published Apr 22, 2022
Tracked Since Feb 18, 2026