CVE-2020-36109

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
01/02/2021
Last modified:
05/02/2021

Description

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-ax86u_firmware:*:*:*:*:*:*:*:* 9.0.0.4_386 (excluding)
cpe:2.3:h:asus:rt-ax86u:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools