OS Command Injection in Asus products - CVE-2023-28702
Published: June 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
GT-AXE16000
GS-AX5400
GT6
TUF-AX5400
RT-AX82U
RT-AX86S
RT-AX86U
RT-AX86U PRO
ZenWiFi XT8_V2
ZenWiFi XT8
ZenWiFi XT9
GT-AX11000
GT-AX6000
GT-AXE11000 PRO
RT-AX58U
RT-AX3000
GT-AXE11000
TUF-AX6000
How to mitigate CVE-2023-28702
GT-AXE16000 - update to 3.0.0.4.388.23012
GS-AX5400 - update to 3.0.0.4.388.23012
GT6 - update to 3.0.0.4.388.23145
TUF-AX5400 - update to 3.0.0.4.388.23285
RT-AX82U - update to 3.0.0.4.388.23285
RT-AX86S - update to 3.0.0.4.388.23285
RT-AX86U - update to 3.0.0.4.388.23285
RT-AX86U PRO - update to 3.0.0.4.388.23285
ZenWiFi XT8_V2 - update to 3.0.0.4.388.23285
ZenWiFi XT8 - update to 3.0.0.4.388.23285
ZenWiFi XT9 - update to 3.0.0.4.388.23285
GT-AX11000 - update to 3.0.0.4.388.23285
GT-AX6000 - update to 3.0.0.4.388.23285
GT-AXE11000 PRO - update to 3.0.0.4.388.23285
RT-AX58U - update to 3.0.0.4.388.23403
RT-AX3000 - update to 3.0.0.4.388.23403
GT-AXE11000 - update to 3.0.0.4.388.23482
TUF-AX6000 - update to 3.0.0.4.388.31927