CVE-2022-26674: critical vulnerability in ASUS RT-AX88U
ASUS RT-AX88U - Format String
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 2.8%
exploitation probability
2.8%top 14% of all CVEs
observed exploitation
nono source reports it
In short
The ASUS RT-AX88U router has a flaw that lets attackers send specially crafted messages to trigger code execution without needing a password. This allows them to take full control of the router.
Technical detail
A format string vulnerability in ASUS RT-AX88U enables an unauthenticated remote attacker to write to arbitrary memory locations via crafted input, leading to arbitrary code execution and complete system compromise. The attack requires network access to the vulnerable service but no prior authentication.
Summary generated and translated by AI from the official description.
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
ASUS · RT-AX88URelated CVEs — ASUS RT-AX88U
In the same product, most dangerous first.
CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2023-41349HIGHASUS RT-AX88U - externally-controlled format stringEPSS 0.9%CVE-2024-3079HIGHASUS Router - Stack-based Buffer OverflowEPSS 0.8%CVE-2023-34359HIGHASUS RT-AX88U - Out-of-bounds Read - 2EPSS 0.8%CVE-2023-34358HIGHASUS RT-AX88U - Out-of-bounds Read - 1EPSS 0.8%CVE-2024-0401HIGHASUS OVPN RCEEPSS 0.7%