CVE-2023-34358: ASUS RT-AX88U - Out-of-bounds Read - 1
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-34358?
CVE-2023-34358 is a vulnerability found in ASUS RT-AX88U's httpd, which allows an unauthenticated remote attacker to cause a denial-of-service (DoS) condition.
How does CVE-2023-34358 work?
A remote attacker can send a specially crafted request to the affected device with a specific user agent, causing the httpd binary to crash and resulting in a DoS condition.
What is the severity of CVE-2023-34358?
The severity of CVE-2023-34358 is high with a CVSS score of 7.5.
Which devices are affected by CVE-2023-34358?
ASUS RT-AX88U devices running firmware up to version 3.0.0.4.388.23748 are affected by CVE-2023-34358.
How can CVE-2023-34358 be mitigated?
As a temporary workaround, users can consider disabling remote access to the affected device or applying the latest firmware update provided by ASUS to address the vulnerability.