CVE-2023-41349: high-severity vulnerability in ASUS RT-AX88U
ASUS RT-AX88U - externally-controlled format string
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
ASUS · RT-AX88URelated CVEs — ASUS RT-AX88U
In the same product, most dangerous first.
CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2022-26674CRITICALASUS RT-AX88U - Format StringEPSS 2.8%CVE-2024-3079HIGHASUS Router - Stack-based Buffer OverflowEPSS 0.8%CVE-2023-34359HIGHASUS RT-AX88U - Out-of-bounds Read - 2EPSS 0.8%CVE-2023-34358HIGHASUS RT-AX88U - Out-of-bounds Read - 1EPSS 0.8%CVE-2024-0401HIGHASUS OVPN RCEEPSS 0.7%