CVE-2022-26674

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6043-0f72c-1.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:rt-ax88u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax88u:-:*:*:*:*:*:*:*

History

04 May 2022, 12:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:h:asus:rt-ax88u:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:rt-ax88u_firmware:*:*:*:*:*:*:*:*
CWE CWE-134
References (MISC) https://www.twcert.org.tw/tw/cp-132-6043-0f72c-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-6043-0f72c-1.html - Third Party Advisory, VDB Entry
First Time Asus
Asus rt-ax88u Firmware
Asus rt-ax88u

22 Apr 2022, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-22 07:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-26674

Mitre link : CVE-2022-26674

CVE.ORG link : CVE-2022-26674


JSON object : View

Products Affected

asus

  • rt-ax88u_firmware
  • rt-ax88u
CWE
CWE-134

Use of Externally-Controlled Format String