CVE-2023-41346: ASUS RT-AX55 - command injection - 2
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-41346?
CVE-2023-41346 is a command injection vulnerability in ASUS RT-AX55 routers that allows an authenticated remote attacker to execute arbitrary commands.
How does CVE-2023-41346 affect ASUS RT-AX55 routers?
ASUS RT-AX55 routers with firmware version 3.0.0.4.386.51598 are vulnerable to CVE-2023-41346.
What is the severity of CVE-2023-41346?
CVE-2023-41346 has a severity score of 8.8 (high).
How can an attacker exploit CVE-2023-41346?
An authenticated remote attacker can exploit CVE-2023-41346 by injecting malicious commands into the ASUS RT-AX55 router to perform unauthorized actions.
Is ASUS RT-AX55 firmware version 3.0.0.4.386.51598 the only affected software?
Yes, ASUS RT-AX55 firmware version 3.0.0.4.386.51598 is the only affected software.