Asus Rt-Ac86U vulnerabilities
16 known vulnerabilities affecting asus/rt-ac86u.
Total CVEs
16
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH13MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-3080CRITICALCVSS 9.8PoC≥ earlier, ≤ 3.0.0.4.386_519152024-06-14
CVE-2024-3080 [CRITICAL] CWE-287 CVE-2024-3080: Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
cvelistv5nvd
CVE-2024-3079HIGHCVSS 7.2≥ earlier, ≤ 3.0.0.4.386_519152024-06-14
CVE-2024-3079 [HIGH] CWE-121 CVE-2024-3079: Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
cvelistv5nvd
CVE-2024-0401HIGHCVSS 7.2fixed in 3.0.0.4.386_519252024-05-20
CVE-2024-0401 [HIGH] CWE-78 CVE-2024-0401: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86,
cvelistv5nvd
CVE-2023-38031HIGHCVSS 8.8v3.0.0.4.386.515292023-09-07
CVE-2023-38031 [HIGH] CWE-78 CVE-2023-38031:
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character.
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
cvelistv5nvd
CVE-2023-38033HIGHCVSS 8.8v3.0.0.4.386.515292023-09-07
CVE-2023-38033 [HIGH] CWE-78 CVE-2023-38033:
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of speci
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
cvelistv5nvd
CVE-2023-39237HIGHCVSS 8.8v3.0.0.4.386.515292023-09-07
CVE-2023-39237 [HIGH] CWE-78 CVE-2023-39237:
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special chara
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
cvelistv5nvd
CVE-2023-39236HIGHCVSS 8.8v3.0.0.4.386.515292023-09-07
CVE-2023-39236 [HIGH] CWE-78 CVE-2023-39236:
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
cvelistv5nvd
CVE-2023-39239HIGHCVSS 7.2v3.0.0.4_386_515292023-09-07
CVE-2023-39239 [HIGH] CWE-134 CVE-2023-39239:
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vul
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt s
cvelistv5nvd
CVE-2023-38032HIGHCVSS 8.8v 3.0.0.4.386.515292023-09-07
CVE-2023-38032 [HIGH] CWE-78 CVE-2023-38032:
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special charact
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.
cvelistv5nvd
CVE-2023-35087CRITICALCVSS 9.8v3.0.0.4_386_515292023-07-21
CVE-2023-35087 [CRITICAL] CWE-134 CVE-2023-35087:
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability i
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform rem
cvelistv5nvd
CVE-2023-35086HIGHCVSS 7.2v3.0.0.4_386_515292023-07-21
CVE-2023-35086 [HIGH] CWE-134 CVE-2023-35086:
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability i
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code ex
cvelistv5nvd
CVE-2023-28703HIGHCVSS 7.2v3.0.0.4.386.512552023-06-02
CVE-2023-28703 [HIGH] CWE-121 CVE-2023-28703: ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insuffi
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.
cvelistv5nvd
CVE-2023-28702HIGHCVSS 8.8v3.0.0.4.386.512552023-06-02
CVE-2023-28702 [HIGH] CWE-78 CVE-2023-28702: ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attac
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.
cvelistv5nvd
CVE-2022-25597HIGHCVSS 8.8v3.0.0.4.386.459562022-04-07
CVE-2022-25597 [HIGH] CWE-78 CVE-2022-25597: ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, w
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.
cvelistv5nvd
CVE-2022-25596HIGHCVSS 8.8v3.0.0.4.386.459562022-04-07
CVE-2022-25596 [HIGH] CWE-787 CVE-2022-25596: ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insuffi
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
cvelistv5nvd
CVE-2022-25595MEDIUMCVSS 6.5v3.0.0.4.386.459562022-04-07
CVE-2022-25595 [MEDIUM] CWE-20 CVE-2022-25595: ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to ca
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
cvelistv5nvd