CVE-2023-28703: ASUS RT-AC86U - Buffer Overflow
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28703?
CVE-2023-28703 is a stack-based buffer overflow vulnerability in the specific cgi function of ASUS RT-AC86U firmware version 3.0.0.4.386.51255, which allows remote attackers with administrator privileges to execute arbitrary system commands.
How does CVE-2023-28703 occur?
CVE-2023-28703 occurs due to insufficient validation for network packet header length in ASUS RT-AC86U's specific cgi function.
What is the severity of CVE-2023-28703?
The severity of CVE-2023-28703 is high, with a severity value of 7.2.
Which software versions are affected by CVE-2023-28703?
ASUS RT-AC86U firmware version 3.0.0.4.386.51255 is affected by CVE-2023-28703.
How can an attacker exploit CVE-2023-28703?
An attacker with administrator privileges can exploit CVE-2023-28703 by sending malicious network packets to the vulnerable device, allowing them to execute arbitrary system commands.