Security News > 2023 > September > ASUS routers vulnerable to critical remote code execution flaws
Three critical-severity remote code execution vulnerabilities impact ASUS RT-AX55, RT-AX56U V2, and RT-AC86U routers, potentially allowing threat actors to hijack devices if security updates are not installed.
The flaws, which all have a CVSS v3.1 score of 9.8 out of 10.0, are format string vulnerabilities that can be exploited remotely and without authentication, potentially allowing remote code execution, service interruptions, and performing arbitrary operations on the device.
Format string flaws are security problems arising from unvalidated and/or unsanitized user input within the format string parameters of certain functions.
Attackers exploit these flaws using specially crafted input sent to the vulnerable devices.
ASUS released patches that address the three flaws in early August 2023 for RT-AX55, in May 2023 for AX56U V2, and in July 2023 for RT-AC86U. Users who haven't applied security updates since then should consider their devices vulnerable to attacks and prioritize the action as soon as possible.
As many consumer router flaws target the web admin console, it is strongly advised to turn off the remote administration feature to prevent access from the internet.
News URL
Related news
- Sophos Firewall vulnerable to critical remote code execution flaw (source)
- Sophos discloses critical Firewall remote code execution flaw (source)
- OvrC Platform Vulnerabilities Expose IoT Devices to Remote Attacks and Code Execution (source)
- QNAP addresses critical flaws across NAS, router software (source)
- Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks (source)
- BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356) (source)
- Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools (source)