Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2q6-vc3h-88w5

Опубликовано: 07 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

EPSS

Процентиль: 87%
0.03202
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость функции iperf файла set_iperf3_svr.cgi прикладного программного интерфейса маршрутизаторов ASUS RT-AX55, RT-AX56U и RT-AC86U, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 87%
0.03202
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-134