CVE-2023-34360: ASUS RT-AX88U - Stored XSS
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior. After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-34360.
What is the severity of CVE-2023-34360?
The severity of CVE-2023-34360 is high.
What is the affected software?
The affected software is ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.
How can a remote attacker exploit CVE-2023-34360?
A remote attacker with regular user privilege can exploit CVE-2023-34360 by performing a stored cross-site scripting (XSS) attack through the Custom User Icons functionality.
Is ASUS RT-AX88U vulnerable to CVE-2023-34360?
Yes, ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior are vulnerable to CVE-2023-34360.