CVE-2022-26674Use of Externally-Controlled Format String in Rt-ax88u

Severity
9.8CRITICALNVD
EPSS
4.5%
top 10.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateApr 23

Description

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5asus/rt-ax88uunspecified3.0.0.4.386.4606
NVDasus/rt-ax88u_firmware< 3.0.0.4.386.46065

🔴Vulnerability Details

2
GHSA
GHSA-c8vq-g263-292w: ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remo2022-04-23
CVEList
ASUS RT-AX88U - Format String2022-04-22
CVE-2022-26674 — Asus Rt-ax88u vulnerability | cvebase