← back
CVE-2022-26674criticalCWE-134

ASUS RT-AX88U - Format String

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 2.6%
exploitation probability
2.6%top 16% of all CVEs
observed exploitation
nono source reports it
In short

The ASUS RT-AX88U router has a flaw that lets attackers send specially crafted messages to trigger code execution without needing a password. This allows them to take full control of the router.

Technical detail

A format string vulnerability in ASUS RT-AX88U enables an unauthenticated remote attacker to write to arbitrary memory locations via crafted input, leading to arbitrary code execution and complete system compromise. The attack requires network access to the vulnerable service but no prior authentication.

Summary generated and translated by AI from the official description.
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
ASUS · RT-AX88U