CVE-2023-39238: ASUS RT-AX55、RT-AX56U_V2 - Format String - 1
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its setiperf3svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Other sources
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its setiperf3svr.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this ASUS RT-AX56U V2 vulnerability?
The vulnerability ID for this ASUS RT-AX56U V2 vulnerability is CVE-2023-39238.
What is the severity of CVE-2023-39238?
The severity of CVE-2023-39238 is critical (CVSS score of 9.8).
How does the format string vulnerability in ASUS RT-AX56U V2 occur?
The format string vulnerability in ASUS RT-AX56U V2 occurs due to lacking validation for a specific value within its set_iperf3_svr.cgi module.
Who can exploit CVE-2023-39238?
CVE-2023-39238 can be exploited by an unauthenticated remote attacker without privilege.
Is there a fix available for this vulnerability?
The fix for this vulnerability may be provided by ASUS in a firmware update.