First published: Fri Nov 03 2023(Updated: )
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax55 Firmware | =3.0.0.4.386.51598 | |
ASUS RT-AX55 |
Update version to 3.0.0.4.386_51948 .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41346 is a command injection vulnerability in ASUS RT-AX55 routers that allows an authenticated remote attacker to execute arbitrary commands.
ASUS RT-AX55 routers with firmware version 3.0.0.4.386.51598 are vulnerable to CVE-2023-41346.
CVE-2023-41346 has a severity score of 8.8 (high).
An authenticated remote attacker can exploit CVE-2023-41346 by injecting malicious commands into the ASUS RT-AX55 router to perform unauthorized actions.
Yes, ASUS RT-AX55 firmware version 3.0.0.4.386.51598 is the only affected software.