PT-2023-25068 · Asus · Asus Rt-N10Lx Router

Published

2023-06-12

·

Updated

2025-01-06

·

CVE-2023-34940

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Asus RT-N10LX Router version 2.0.0.39
Description A stack overflow issue was discovered via the url parameter at the "/start-apply.html" API endpoint. This issue only affects products that are no longer supported by the maintainer.
Recommendations For Asus RT-N10LX Router version 2.0.0.39, as a temporary workaround, consider restricting access to the "/start-apply.html" API endpoint to minimize the risk of exploitation. Avoid using the url parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-34940

Affected Products

Asus Rt-N10Lx Router