Asus
Asus Rt-ac86u Firmware: vulnerabilidades y CVE
Asus Rt-ac86u Firmware tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-39240 | Alta (7.2) | 1.3% | — | 7 sept 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote… |
| CVE-2023-39239 | Alta (7.2) | 1.3% | — | 7 sept 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with… |
| CVE-2023-39238 | Alta (7.2) | 1.4% | — | 7 sept 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator… |
| CVE-2023-39237 | Alta (8.8) | 1.4% | — | 7 sept 2023 | ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack… |
| CVE-2023-39236 | Alta (8.8) | 1.4% | — | 7 sept 2023 | ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to… |
| CVE-2023-38033 | Alta (8.8) | 1.4% | — | 7 sept 2023 | ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection… |
| CVE-2023-38032 | Alta (8.8) | 1.4% | — | 7 sept 2023 | ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to… |
| CVE-2023-38031 | Alta (8.8) | 1.4% | — | 7 sept 2023 | ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to… |
| CVE-2023-35087 | Crítica (9.8) | 1.1% | — | 21 jul 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in… |
| CVE-2023-35086 | Alta (7.2) | 39% | — | 21 jul 2023 | It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the… |
| CVE-2023-28703 | Alta (7.2) | 0.89% | — | 2 jun 2023 | ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this… |
| CVE-2023-28702 | Alta (8.8) | 1.2% | — | 2 jun 2023 | ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary… |
| CVE-2021-43702 | Crítica (9) | 0.98% | — | 5 jul 2022 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom… |
| CVE-2022-25597 | Alta (8.8) | 0.78% | — | 7 abr 2022 | ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt… |
| CVE-2022-25596 | Alta (8.8) | 0.59% | — | 7 abr 2022 | ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary… |
| CVE-2022-25595 | Media (6.5) | 0.40% | — | 7 abr 2022 | ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt. |
| CVE-2021-3128 | Alta (7.5) | 2.2% | — | 12 abr 2021 | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic… |
| CVE-2018-8826 | Crítica (9.8) | 4.2% | — | 20 abr 2018 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and… |
| CVE-2018-9285 | Crítica (9.8) | 3.6% | — | 4 abr 2018 | Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and… |