cve/2023/CVE-2023-39240.md
2024-05-25 21:48:12 +02:00

1.2 KiB
Raw Blame History

CVE-2023-39240

Description

It is identified a format string vulnerability in ASUS RT-AX56U V2s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

POC

Reference

No PoCs from references.

Github