CVE-2023-34359: ASUS RT-AX88U - Out-of-bounds Read - 2
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "dojsondecode()" function of ej.c, resulting in a DoS condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-34359.
What is the severity level of CVE-2023-34359?
The severity level of CVE-2023-34359 is high.
How does this vulnerability affect ASUS RT-AX88U?
This vulnerability affects ASUS RT-AX88U, specifically the firmware version up to 3.0.0.4.388.23748.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by sending a specially crafted request to ASUS RT-AX88U, causing the httpd binary to crash and resulting in a denial-of-service (DoS) condition.
Is there a fix for CVE-2023-34359?
At the moment, there is no known fix for CVE-2023-34359. It is recommended to follow the vendor's security advisory for updates or patches.