First published: Mon Jul 31 2023(Updated: )
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior. After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax88u Firmware | <=3.0.0.4.388.23110 | |
ASUS RT-AX88U |
Update firmware version to 3.0.0.4_388_23748 or latest
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-34360.
The severity of CVE-2023-34360 is high.
The affected software is ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.
A remote attacker with regular user privilege can exploit CVE-2023-34360 by performing a stored cross-site scripting (XSS) attack through the Custom User Icons functionality.
Yes, ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior are vulnerable to CVE-2023-34360.