CVE-2023-35086
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 75.07%
- CWE
- CWE-134
- Published
- 2023-07-21
- Last modified
- 2026-03-13
Affected products
- ASUS RT-AX56U V2
- ASUS RT-AC86U
Weakness type
Related vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2012-10055 — ComSndFTP v1.3.7 Beta USER Format String RCE
- CVE-2020-3118 — Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
- CVE-2011-10029 — Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
- CVE-2022-26674 — ASUS RT-AX88U - Format String
- CVE-2022-34747 — A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach
- CVE-2021-41193 — Use of Externally-Controlled Format String in wire-avs
- CVE-2023-35087 — ASUS RT-AX56U V2 & RT-AC86U - Format String - 2