← Back

Rt Ac86u Firmware

rt-ac86u_firmware

Vendor: Asus • 19 CVEs

CVEs (19)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote atta...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with adm...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator priv...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack t...Show more
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to ex...Show more
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection...Show more
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to...Show more
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to exec...Show more
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. Show less
1Asus
2Rt Ac86u Firmware
Rt Ax56u V2 Firmware
Nov 21, 2024
Jul 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CO...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.Show less
1Asus
2Rt Ac86u Firmware
Rt Ax56u V2 Firmware
Nov 21, 2024
Jul 21, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529. Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Jun 2, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vuln...Show more
ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service.Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Jun 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary...Show more
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service.Show less
1Asus
904g Ac53u Firmware
4g Ac68u FirmwareRog Rapture Gt Ac2900 Firmware+87 more
Nov 21, 2024
Jul 5, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom pa...Show more
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt...Show more
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary...Show more
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.Show less
1Asus
1Rt Ac86u Firmware
Nov 21, 2024
Apr 7, 2022
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
1Asus
27Rt Ac1750 B1 Firmware
Rt Ac1900 FirmwareRt Ac1900p Firmware+24 more
Nov 21, 2024
Apr 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between...Show more
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.Show less
1Asus
13Rt Ac1200 Firmware
Rt Ac1750 FirmwareRt Ac2900 Firmware+10 more
Nov 21, 2024
Apr 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC5...Show more
ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.Show less
1Asus
11Rt Ac1900 Firmware
Rt Ac2900 FirmwareRt Ac3100 Firmware+8 more
Nov 21, 2024
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC32...Show more
Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS command injection via the pingCNT and destIP fields of the SystemCmd variable.Show less