Podatność CVE-2023-41349


Publikacja: 2023-09-18   Modyfikacja: 2023-09-19

Opis:

ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service.

Typ:

CWE-134

(Uncontrolled Format String)

 Referencje:
https://www.twcert.org.tw/tw/cp-132-7371-aecf1-1.html

Copyright 2024, cxsecurity.com

 

Back to Top