HIGH

CVE-2023-39780

Asus Rt Ax55 Firmware 2023-09-11 CVSS v3.1
CVSS
8.8
KEV

Description

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

Summary dbcve.org

Authenticated OS command injection vulnerability in ASUS RT-AX55 router firmware 3.0.0.4.386.51598. Attackers with valid web interface credentials can inject arbitrary OS commands through the qos_bw_rulelist parameter in the /start_apply.htm endpoint, allowing complete system compromise.

Mitigation

Apply vendor firmware update when available; otherwise restrict web management interface access to trusted IPs only or disable remote management.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

40.19%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE