First published: Thu Sep 07 2023(Updated: )
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ac86u Firmware | =3.0.0.4_386_51529 | |
ASUS RT-AC86U |
Update to 3.0.0.4.386_51915
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38032 is a vulnerability in the ASUS RT-AC86U AiProtection security-related function that allows a remote attacker to perform command injection attacks.
CVE-2023-38032 affects the ASUS RT-AC86U router firmware version 3.0.0.4_386_51529, allowing a remote attacker with regular user privilege to execute arbitrary commands.
CVE-2023-38032 has a severity rating of 8.8, which is classified as high.
An attacker can exploit CVE-2023-38032 by injecting specially crafted commands, which can lead to the execution of arbitrary commands, system disruption, or termination of services.
To fix CVE-2023-38032, it is recommended to update the ASUS RT-AC86U router firmware to a version that addresses the vulnerability.