CVE-2023-41349

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
18/09/2023
Last modified:
19/09/2023

Description

<br /> ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-ax88u_firmware:*:*:*:*:*:*:*:* 3.0.0.4.388.23748 (excluding)
cpe:2.3:h:asus:rt-ax88u:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools