← Vulnerability feed

Vulnerability record · CVE-2023-35087 · published 21 July 2023

CVE-2023-35087: Asus rt-ac86u firmware vulnerability

Asus · Rt Ac86u Firmware

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

9.8 CVSS 3.1 Critical EPSS 1.1% · top 36.6% CWE-134 · CWE-134
9.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35087 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41435Asus gt-ax11000 firmware improper restriction of authentication attempts vulnerabilityA brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, …EPSS 6.5%9.8CVE-2018-8826Asus rt-ac51u firmware improper input validation vulnerabilityASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N…EPSS 4.3%9.8CVE-2018-9285Asus rt-ac66u firmware os command injection vulnerabilityMain_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.38…EPSS 3.6%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.8CVE-2023-38032Asus rt-ac86u firmware os command injection vulnerabilityASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege …EPSS 1.4%8.8CVE-2023-38033Asus rt-ac86u firmware os command injection vulnerabilityASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user …EPSS 1.4%8.8CVE-2023-39236Asus rt-ac86u firmware os command injection vulnerabilityASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege ca…EPSS 1.4%8.8CVE-2023-39237Asus rt-ac86u firmware os command injection vulnerabilityASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privileg…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-35087), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.