Vulnerability Details CVE-2021-40556
A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability allows an attacker to execute commands remotely. The vulnerability requires authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2021-40556
-
cpe:2.3:h:asus:rt-ax56u:-
-
cpe:2.3:o:asus:rt-ax56u_firmware:3.0.0.4.386.44266