Vulnerability Details CVE-2023-39238
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.031
EPSS Ranking 86.1%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2023-39238
-
cpe:2.3:h:asus:rt-ac86u:-
-
-
cpe:2.3:h:asus:rt-ax56u_v2:-
-
cpe:2.3:o:asus:rt-ac86u_firmware:3.0.0.4_386_51529
-
cpe:2.3:o:asus:rt-ax55_firmware:3.0.0.4.386_50460
-
cpe:2.3:o:asus:rt-ax56u_v2_firmware:3.0.0.4.386_50460