CVE-2023-34358
HIGH7.5CVSS v3
—CVSS v2
0.36%
EPSS (exploit probability)
CWE-125CWE
Description
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected routers (1)
| Vendor | Model | Matched via | Affected versions | Fixed in | Patch Status |
|---|---|---|---|---|---|
| ASUS | ASUS RT-AX88U | — |
versionEndExcluding=3.0.0.4.388.23748 | 3.0.0.4.388.23748 | Patched |