PT-2023-7096 · Asus · Asus Rt-Ax57
Published
2023-10-09
·
Updated
2024-01-19
·
CVE-2023-47005
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AX57 version 3.0.0.4 386 52041
Description
The issue exists due to insufficient input validation in the sub ln 2C318 function of the Wi-Fi router's microprogram. Exploitation of this issue may allow a remote attacker to execute arbitrary code by sending a specially crafted request to the
lan ifname field.Recommendations
For version 3.0.0.4 386 52041, consider disabling the
sub ln 2C318 function until a patch is available to prevent exploitation. Restrict access to the lan ifname field in the affected function to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ax57