CVE-2023-39780
published 2023-09-11CVE-2023-39780: On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE…
PriorityP187high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-06-23
Exploited in the wild
EPSS
33.64%
98.2th percentile
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | rt-ax55 | — | — |
| asus | rt-ax55_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check ASUS routers for SSH listening on non-standard port TCP/53282, which is the backdoor port installed by the AyySSHush campaign exploiting CVE-2023-39780. ↗
- →Inspect the router's authorized_keys file for unauthorized SSH public key entries beginning with 'ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAo41nBoVFfj4HlVMGV+YPsxMDrMlbdDZ'. ↗
- →Monitor for HTTP POST requests targeting /start_apply.htm with the qos_bw_rulelist parameter, which is the injection vector for CVE-2023-39780. ↗
- →Sift flagged just three HTTP POST requests — targeting ASUS router endpoints — for deeper inspection; even very low-volume POST traffic to ASUS router management endpoints should be investigated. ↗
- →Detect presence of a self-signed TLS certificate with a 100-year lifetime on AiCloud services as an indicator of compromise in the WrtHug/AyySSHush campaign. ↗
- →The backdoor is stored in NVRAM, so it persists across firmware upgrades and reboots; a firmware update alone will NOT remove the SSH backdoor if the router was previously compromised. ↗
- →Attackers disable router logging and Trend Micro's AiProtection as part of the exploitation chain; absence of logs on a potentially compromised device should itself be treated as a suspicious indicator. ↗
- ·The attacker's SSH public key and port 53282 configuration are stored in NVRAM (non-volatile memory), not on disk, so they survive both reboots and firmware upgrades. A full factory reset followed by manual reconfiguration is required to remove the backdoor. ↗
- ·The initial authentication bypass techniques used in the exploitation chain have not been assigned CVEs, meaning CVE-based patch tracking alone is insufficient to confirm a device is protected. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6m5p-5ccp-c8p3: ASUS RT-AX55 v3
ghsa_unreviewed·2023-09-11
CVE-2023-39780 [HIGH] CWE-77 GHSA-6m5p-5ccp-c8p3: ASUS RT-AX55 v3
ASUS RT-AX55 v3.0.0.4.386.51598 was discovered to contain an authenticated command injection vulnerability.
VulnCheck
ASUS RT-AX55 Routers OS Command Injection Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-39780 [HIGH] CWE-78 ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
Affected: ASUS RT-AX55 Routers
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers; https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/; https://censys.com/blog/tracking-ayysshush-a-newly-discovered-asus-router-botnet-campaign; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json;
CISA
ASUS RT-AX55 Routers OS Command Injection Vulnerability
cisa·2025-06-02·CVSS 8.8
CVE-2023-39780 [HIGH] CWE-78 ASUS RT-AX55 Routers OS Command Injection Vulnerability
Vulnerability: ASUS RT-AX55 Routers OS Command Injection Vulnerability
Affected: ASUS RT-AX55 Routers
ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.asus.com/networking-iot-servers/wifi-6/all-series/rt-ax55/helpdesk_bios/?model2Name=RT-AX55 ; https://www.asus.com/content/asus-product-security-advisory/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-39780
Remediation Due Date: 2025-06-23
Suricata
ET WEB_SPECIFIC_APPS ASUS AiProtection_HomeProtection.asp oauth_google_auth_code Parameter Command Injection Attempt (CVE-2023-39780)
suricata·2025-05-28·CVSS 8.8
CVE-2023-39780 [HIGH] ET WEB_SPECIFIC_APPS ASUS AiProtection_HomeProtection.asp oauth_google_auth_code Parameter Command Injection Attempt (CVE-2023-39780)
ET WEB_SPECIFIC_APPS ASUS AiProtection_HomeProtection.asp oauth_google_auth_code Parameter Command Injection Attempt (CVE-2023-39780)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS ASUS AiProtection_HomeProtection.asp oauth_google_auth_code Parameter Command Injection Attempt (CVE-2023-39780)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:16; content:"/start_apply.htm"; fast_pattern; http.request_body; content:"current_page=AiProtection_HomeProtection.asp"; content:"oauth_google_auth_code|3d|"; pcre:"/^(?:\x27|%27).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/R"; reference:url,github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.md; reference:cve,2023-39780; classtype:attempted-admi
No public exploits indexed.
Bleepingcomputer
New WrtHug campaign hijacks thousands of end-of-life ASUS routers
blogs_bleepingcomputer·2025-11-19·CVSS 8.8
[HIGH] New WrtHug campaign hijacks thousands of end-of-life ASUS routers
## New WrtHug campaign hijacks thousands of end-of-life ASUS routers
## Bill Toulas
Thousands of ASUS WRT routers, mostly end-of-life or outdated devices, have been hijacked in a global campaign called Operation WrtHug that exploits six vulnerabilities.
Over the past six months, scanners looking for ASUS devices compromised in Operation WrtHug identified "roughly 50,000 unique IPs" around the globe.
Most of the compromised devices have IP addresses located in Taiwan, while others are distributed across Southeast Asia, Russia, Central Europe, and the United States.
Notably, there are no observed infections within China, which may indicate a threat actor from this country, but researchers found insufficient evidence for high-confidence attribution.
According to SecurityScorecard’s STRI
Bleepingcomputer
ASUS warns of critical auth bypass flaw in DSL series routers
blogs_bleepingcomputer·2025-11-14·CVSS 9.3
CVE-2025-59367 [CRITICAL] ASUS warns of critical auth bypass flaw in DSL series routers
## ASUS warns of critical auth bypass flaw in DSL series routers
## Sergiu Gatlan
ASUS has released new firmware to patch a critical authentication bypass security flaw impacting several DSL series router models.
Tracked as CVE-2025-59367 , this vulnerability allows remote, unauthenticated attackers to log into unpatched devices exposed online in low-complexity attacks that don't require user interaction.
ASUS has released firmware version 1.1.2.3_1010 to address this vulnerability for DSL-AC51, DSL-N16, and DSL-AC750 router models.
"An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system," ASUS explains .
"ASUS recommends update to the latest firmware to ensure your devi
Bleepingcomputer
CISA warns of ConnectWise ScreenConnect bug exploited in attacks
blogs_bleepingcomputer·2025-06-03·CVSS 9.8
[CRITICAL] CISA warns of ConnectWise ScreenConnect bug exploited in attacks
## CISA warns of ConnectWise ScreenConnect bug exploited in attacks
## Ionut Ilascu
CISA is alerting federal agencies in the U.S. of hackers exploiting a recently patched ScreenConnect vulnerability that could lead to executing remote code on the server.
The agency is warning that four other security problems affecting ASUS routers and the Craft content management system (CMS) are also actively exploited.
## Improper authentication in ConnectWise ScreenConnect
On April 24, ConnectWise addressed the security issue, tracked as CVE-2025-3935, stating that the vulnerability could be exploited for a ViewState code injection attack.
The vendor notes that ASP.NET Web Forms rely on the ViewState component to preserve page and control state using base64-encoded data that is protected by machi
Greynoiseio
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
blogs_greynoiseio·2025-05-28
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bleepingcomputer
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
blogs_bleepingcomputer·2025-05-28·CVSS 9.8
[CRITICAL] Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
## Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
## Bill Toulas
Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys.
The campaign was discovered by GreyNoise security researchers in mid-March 2025, who reports that it carries the hallmarks of a nation-state threat actor, though no concrete attributions were made.
The threat monitoring firm reports that the attacks combine brute-forcing login credentials, bypassing authentication, and exploiting older vulnerabilities to compromise ASUS routers, including the RT-AC3100, RT-AC3200, and RT-AX55 models.
Specifically, the attackers exploit an old command injection flaw tracked as CVE-2023-39780 to add their own SSH public
Greynoiseio
NoiseLetter March 2025
blogs_greynoiseio
NoiseLetter March 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.mdhttps://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.mdhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-39780https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers
2023-09-11
Published
2025-06-02
Added to CISA KEV
Exploited in the wild