CVE-2023-38031: ASUS RT-AC86U - Command injection vulnerability - 1
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-38031?
CVE-2023-38031 is a vulnerability in ASUS RT-AC86U Adaptive QoS - Web History function that allows a remote attacker to perform command injection attacks.
What is the severity of CVE-2023-38031?
The severity of CVE-2023-38031 is high with a CVSS score of 8.8.
How can a remote attacker exploit CVE-2023-38031?
A remote attacker with regular user privilege can exploit CVE-2023-38031 by performing a command injection attack to execute arbitrary commands, disrupt system, or terminate services.
Is ASUS RT-AC86U firmware version 3.0.0.4_386_51529 affected by CVE-2023-38031?
Yes, ASUS RT-AC86U firmware version 3.0.0.4_386_51529 is affected by CVE-2023-38031.
Where can I find more information about CVE-2023-38031?
You can find more information about CVE-2023-38031 at this link: [https://www.twcert.org.tw/tw/cp-132-7348-56989-1.html](https://www.twcert.org.tw/tw/cp-132-7348-56989-1.html)