CVE-2023-39240

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Sep 7, 2023
Updated: Mar 27, 2024
CWE ID 134

Summary

CVE-2023-39240 is a format string vulnerability affecting the iperf client function API in ASUS RT-AX56U V2. The issue arises due to insufficient validation of a particular input value within the set_iperf3_cli.cgi module. A remote attacker, having administrative privileges, can exploit this flaw for arbitrary code execution, system operations, or denial-of-service attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share