← Back to browse · API

CVE-2023-35086

Severity
HIGH
CVSS
7.2
EPSS
0.385
Risk score
42.27
CISA KEV
No
PoC
No
Published
2023-07-21
Modified
2024-10-24
First seen
2026-08-07
Aliases
EUVD-2023-39121, GHSA-R4FX-9V33-WCF4
Products
ASUS:RT-AC86U 3.0.0.4_386_51529, ASUS:RT-AX56U V2 3.0.0.4.386_50460
Sources
euvd EUVD-2023-39121

Description

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

References