Vulnerabilities > Asus > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-07 CVE-2023-38032 OS Command Injection vulnerability in Asus Rt-Ac86U Firmware 3.0.0.438651529
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character.
network
low complexity
asus CWE-78
8.8
2023-09-07 CVE-2023-38033 OS Command Injection vulnerability in Asus Rt-Ac86U Firmware 3.0.0.438651529
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character.
network
low complexity
asus CWE-78
8.8
2023-09-07 CVE-2023-39237 OS Command Injection vulnerability in Asus Rt-Ac86U Firmware 3.0.0.438651529
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character.
network
low complexity
asus CWE-78
8.8
2023-09-07 CVE-2023-38031 Unspecified vulnerability in Asus Rt-Ac86U Firmware 3.0.0.438651529
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character.
network
low complexity
asus
8.8
2023-08-08 CVE-2023-39086 Cleartext Transmission of Sensitive Information vulnerability in Asus Rt-Ac66U B1 Firmware 3.0.0.4.28651665
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
network
low complexity
asus CWE-319
7.5
2023-07-31 CVE-2023-34358 Out-of-bounds Read vulnerability in Asus Rt-Ax88U Firmware
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition.
network
low complexity
asus CWE-125
7.5
2023-07-31 CVE-2023-34359 Out-of-bounds Read vulnerability in Asus Rt-Ax88U Firmware
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition.
network
low complexity
asus CWE-125
7.5
2023-07-26 CVE-2023-26911 Unquoted Search Path or Element vulnerability in Asus Armoury Crate and Setupasusservices
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
local
low complexity
asus CWE-428
7.8
2023-07-21 CVE-2023-35086 Use of Externally-Controlled Format String vulnerability in Asus Rt-Ac86U Firmware and Rt-Ax56U V2 Firmware
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U.
network
low complexity
asus CWE-134
7.2
2023-06-12 CVE-2023-34940 Out-of-bounds Write vulnerability in Asus Rt-N10Lx Firmware 2.0.0.39
Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html.
network
low complexity
asus CWE-787
7.5