CVE-2023-35086: high-severity vulnerability in ASUS RT-AX56U V2
ASUS RT-AX56U V2 & RT-AC86U - Format String -1
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A format string vulnerability in ASUS routers allows an attacker with admin access to send specially crafted input that gets mishandled by the logging function, potentially leading to unauthorized code execution or system disruption.
A format string vulnerability exists in the logmessage_normal function of the do_detwan_cgi module within httpd, where unsanitized user input is passed directly as a format string to syslog. An authenticated remote attacker can leverage this to achieve arbitrary code execution, arbitrary system operations, or denial of service on affected RT-AX56U V2 and RT-AC86U devices.
In the same product, most dangerous first.