Asus Rt-Ax56U V2 Firmware vulnerabilities
7 known vulnerabilities affecting asus/rt-ax56u_v2_firmware.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5
Vulnerabilities
Page 1 of 1
CVE-2023-39238HIGHCVSS 7.2v3.0.0.4.386_504602023-09-07
CVE-2023-39238 [HIGH] CWE-134 CVE-2023-39238:
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
nvd
CVE-2023-39240HIGHCVSS 7.2v3.0.0.4.386_504602023-09-07
CVE-2023-39240 [HIGH] CWE-134 CVE-2023-39240:
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. Thi
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operatio
nvd
CVE-2023-39239HIGHCVSS 7.2v3.0.0.4.386_504602023-09-07
CVE-2023-39239 [HIGH] CWE-134 CVE-2023-39239:
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vul
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt s
nvd
CVE-2023-35087CRITICALCVSS 9.8v3.0.0.4.386_504602023-07-21
CVE-2023-35087 [CRITICAL] CWE-134 CVE-2023-35087:
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability i
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform rem
nvd
CVE-2023-35086HIGHCVSS 7.2v3.0.0.4.386_504602023-07-21
CVE-2023-35086 [HIGH] CWE-134 CVE-2023-35086:
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability i
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code ex
nvd
CVE-2021-41435CRITICALCVSS 9.8fixed in 3.0.0.4.386.458982021-11-19
CVE-2021-41435 [CRITICAL] CWE-307 CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) bef
nvd
CVE-2021-41436HIGHCVSS 7.5fixed in 3.0.0.4.386.458982021-11-19
CVE-2021-41436 [HIGH] CWE-444 CVE-2021-41436: An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.3
nvd