Stack-based buffer overflow in Asus products - CVE-2023-28703

 

Stack-based buffer overflow in Asus products - CVE-2023-28703

Published: June 20, 2023


Vulnerability identifier: #VU77537
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28703
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the cgi function. A remote administrator can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

GS-AX3000
GT-AXE16000
GS-AX5400
GT6
TUF-AX5400
RT-AX82U
RT-AX86S
RT-AX86U
RT-AX86U PRO
ZenWiFi XT8_V2
ZenWiFi XT8
ZenWiFi XT9
GT-AX11000
GT-AX6000
GT-AXE11000 PRO
RT-AX58U
RT-AX3000
GT-AXE11000
TUF-AX6000

How to mitigate CVE-2023-28703

Install updates from vendor's website.

GS-AX3000 - update to 1.4.8.3
GT-AXE16000 - update to 3.0.0.4.388.23012
GS-AX5400 - update to 3.0.0.4.388.23012
GT6 - update to 3.0.0.4.388.23145
TUF-AX5400 - update to 3.0.0.4.388.23285
RT-AX82U - update to 3.0.0.4.388.23285
RT-AX86S - update to 3.0.0.4.388.23285
RT-AX86U - update to 3.0.0.4.388.23285
RT-AX86U PRO - update to 3.0.0.4.388.23285
ZenWiFi XT8_V2 - update to 3.0.0.4.388.23285
ZenWiFi XT8 - update to 3.0.0.4.388.23285
ZenWiFi XT9 - update to 3.0.0.4.388.23285
GT-AX11000 - update to 3.0.0.4.388.23285
GT-AX6000 - update to 3.0.0.4.388.23285
GT-AXE11000 PRO - update to 3.0.0.4.388.23285
RT-AX58U - update to 3.0.0.4.388.23403
RT-AX3000 - update to 3.0.0.4.388.23403
GT-AXE11000 - update to 3.0.0.4.388.23482
TUF-AX6000 - update to 3.0.0.4.388.31927

External References

Related Security Bulletins