First published: Mon Jul 31 2023(Updated: )
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax88u Firmware | <3.0.0.4.388.23748 | |
ASUS RT-AX88U |
Update firmware version to 3.0.0.4_388_23748
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34358 is a vulnerability found in ASUS RT-AX88U's httpd, which allows an unauthenticated remote attacker to cause a denial-of-service (DoS) condition.
A remote attacker can send a specially crafted request to the affected device with a specific user agent, causing the httpd binary to crash and resulting in a DoS condition.
The severity of CVE-2023-34358 is high with a CVSS score of 7.5.
ASUS RT-AX88U devices running firmware up to version 3.0.0.4.388.23748 are affected by CVE-2023-34358.
As a temporary workaround, users can consider disabling remote access to the affected device or applying the latest firmware update provided by ASUS to address the vulnerability.