Asus Rt-Ax88U vulnerabilities
9 known vulnerabilities affecting asus/rt-ax88u.
Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-3080CRITICALCVSS 9.8PoC≥ earlier, ≤ 3.0.0.4.388_241982024-06-14
CVE-2024-3080 [CRITICAL] CWE-287 CVE-2024-3080: Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
cvelistv5nvd
CVE-2024-3079HIGHCVSS 7.2≥ earlier, ≤ 3.0.0.4.388_241982024-06-14
CVE-2024-3079 [HIGH] CWE-121 CVE-2024-3079: Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with
Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.
cvelistv5nvd
CVE-2024-0401HIGHCVSS 7.2fixed in 3.0.0.4.388_242092024-05-20
CVE-2024-0401 [HIGH] CWE-78 CVE-2024-0401: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86,
cvelistv5nvd
CVE-2023-41349HIGHCVSS 8.8≥ , < 3.0.0.4_388_237482023-09-18
CVE-2023-41349 [HIGH] CWE-134 CVE-2023-41349:
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and perman
cvelistv5nvd
CVE-2023-34358HIGHCVSS 7.5≥ , ≤ 3.0.0.4.388_22525-gd35b8fe2023-07-31
CVE-2023-34358 [HIGH] CWE-125 CVE-2023-34358: ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a s
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
cvelistv5nvd
CVE-2023-34359HIGHCVSS 7.5≥ , ≤ 3.0.0.4.388_22525-gd35b8fe2023-07-31
CVE-2023-34359 [HIGH] CWE-125 CVE-2023-34359: ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a s
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
cvelistv5nvd
CVE-2023-34360MEDIUMCVSS 5.4≥ , ≤ 3.0.0.4.388.231102023-07-31
CVE-2023-34360 [HIGH] CWE-79 CVE-2023-34360: A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality
A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior. After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing J
cvelistv5nvd
CVE-2022-26674CRITICALCVSS 9.8≥ unspecified, < 3.0.0.4.386.46062022-04-22
CVE-2022-26674 [CRITICAL] CWE-134 CVE-2022-26674: ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
cvelistv5nvd
CVE-2022-26673MEDIUMCVSS 5.4≥ unspecified, < 3.0.0.4.386.46062022-04-22
CVE-2022-26673 [MEDIUM] CWE-79 CVE-2022-26673: ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remo
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
cvelistv5nvd