PT-2023-7593 · Asus · Asus Rt-Ac86U+1
Published
2023-07-17
·
Updated
2023-08-03
·
CVE-2023-35087
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS RT-AX56U V2 version 3.0.0.4.386 50460
ASUS RT-AC86U version 3.0.0.4 386 51529
Description
The issue is related to a format string vulnerability in the
cm processChangedConfigMsg function of the AiMesh system. This vulnerability is caused by a lack of validation for a specific value when calling cm processChangedConfigMsg in the ccm processREQ CHANGED CONFIG function. An unauthenticated remote attacker can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation, or disrupt service.Recommendations
For ASUS RT-AX56U V2 version 3.0.0.4.386 50460, update to a newer version that contains a fix for this issue.
For ASUS RT-AC86U version 3.0.0.4 386 51529, update to a newer version that contains a fix for this issue.
As a temporary workaround, consider disabling the
cm processChangedConfigMsg function in the AiMesh system until a patch is available.Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ac86U
Asus Rt-Ax56U V2