Back

HIGH

ASUS RT-AX88U - externally-controlled format string

Published Sep 18, 2023

Description

ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.

Affected products

Remediation

Vendor solution

Update the version to 3.0.0.4_388_23748 or later.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Sep 18, 2023
Updated Sep 25, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Sep 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Sep 18, 2023
Updated Sep 25, 2024
Exploited since n/a
EUVD-2023-45852