ASUS RT-A88U 3.0.0.4.38645898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
blockingrequest.cgi on ASUS GT-AC5300 devices through 3.0.0.4.38432738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.38432738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long shpath0 value and then sending an appGet.cgi?hook=selectlist("StoragexSharedPath") request, because ejselectlist in router/httpd/web.c uses strcpy.
ASUS GT-AC5300 devices with firmware through 3.0.0.4.38432738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line.
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.38432738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.38432738 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to startapply.htm.