CVE-2023-35086
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Jul 21, 2023
Updated: Mar 27, 2024
CWE ID 134
Summary
CVE-2023-35086 is a format string vulnerability affecting the ASUS RT-AX56U V2 and RT-AC86U routers. The flaw resides in the logmessage_normal function of the do_detwan_cgi module in httpd. An attacker with administrator privileges can manipulate input as a format string, leading to remote arbitrary code execution, arbitrary system operations, or denial-of-service attacks. This vulnerability affects RT-AX56U V2 with firmware version 3.0.0.4.386_50460 and RT-AC86U with firmware version 3.0.0.4_386_51529.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- ASUS