Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vqq-6vgg-h45h

Опубликовано: 07 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

EPSS

Процентиль: 74%
0.00848
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость прикладного программного интерфейса маршрутизаторов ASUS RT-AX55, RT-AX56U и RT-AC86U, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 74%
0.00848
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-134