CVE-2023-39240
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Sep 7, 2023
Updated: Mar 27, 2024
CWE ID 134
Summary
CVE-2023-39240 is a format string vulnerability affecting the iperf client function API in ASUS RT-AX56U V2. The issue arises due to insufficient validation of a particular input value within the set_iperf3_cli.cgi module. A remote attacker, having administrative privileges, can exploit this flaw for arbitrary code execution, system operations, or denial-of-service attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- ASUS