Back

HIGH

ASUS RT-AX55 - command injection - 1

Published Nov 3, 2023

Description

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.

Affected products

Remediation

Vendor solution

Update version to 3.0.0.4.386_51948 .

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Nov 3, 2023
Updated Sep 6, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Sep 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a