Asus Rt-Ax88U Firmware vulnerabilities

11 known vulnerabilities affecting asus/rt-ax88u_firmware.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-41349HIGHCVSS 8.8fixed in 3.0.0.4.388.237482023-09-18
CVE-2023-41349 [HIGH] CWE-134 CVE-2023-41349: ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and perman
nvd
CVE-2023-34358HIGHCVSS 7.5fixed in 3.0.0.4.388.237482023-07-31
CVE-2023-34358 [HIGH] CWE-125 CVE-2023-34358: ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a s ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
nvd
CVE-2023-34359HIGHCVSS 7.5fixed in 3.0.0.4.388.237482023-07-31
CVE-2023-34359 [HIGH] CWE-125 CVE-2023-34359: ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a s ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
nvd
CVE-2023-34360MEDIUMCVSS 5.4≤ 3.0.0.4.388.231102023-07-31
CVE-2023-34360 [HIGH] CWE-79 CVE-2023-34360: A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior. After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing J
nvd
CVE-2021-41437MEDIUMCVSS 6.5fixed in 3.0.0.4.388.205582022-09-26
CVE-2021-41437 [MEDIUM] CWE-74 CVE-2021-41437: An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allo An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
nvd
CVE-2021-43702CRITICALCVSS 9.0v3.0.0.4.386.460612022-07-05
CVE-2021-43702 [CRITICAL] CWE-79 CVE-2021-43702: ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin pa ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
nvd
CVE-2022-26674CRITICALCVSS 9.8fixed in 3.0.0.4.386.460652022-04-22
CVE-2022-26674 [CRITICAL] CWE-134 CVE-2022-26674: ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
nvd
CVE-2022-26673MEDIUMCVSS 5.4fixed in 3.0.0.4.386.460652022-04-22
CVE-2022-26673 [MEDIUM] CWE-79 CVE-2022-26673: ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remo ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
nvd
CVE-2021-41435CRITICALCVSS 9.8fixed in 3.0.0.4.386.458982021-11-19
CVE-2021-41435 [CRITICAL] CWE-307 CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT- A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) bef
nvd
CVE-2021-41436HIGHCVSS 7.5fixed in 3.0.0.4.386.458982021-11-19
CVE-2021-41436 [HIGH] CWE-444 CVE-2021-41436: An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT- An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.3
nvd
CVE-2021-3128HIGHCVSS 7.5fixed in 3.0.0.4.386.42095fixed in 9.0.0.4.386.419942021-04-12
CVE-2021-3128 [HIGH] CWE-834 CVE-2021-3128: In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42 In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination
nvd