Skip to main content

Vendor/product archive

asus / rt-ax88u CVEs

Beta · best-effort

10 CVEs tagged to asus / rt-ax88u2 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-41349

Published Sep 18, 2023

ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the ex…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34360

Published Jul 31, 2023

A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34359

Published Jul 31, 2023

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34358

Published Jul 31, 2023

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41437

Published Sep 26, 2022

An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26674

Published Apr 22, 2022

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26673

Published Apr 22, 2022

ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to injec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1