Vulnerability record · CVE-2023-39780 · published 11 September 2023
CVE-2023-39780: ASUS RT-AX55 Router OS Command Injection via qos_bw_rulelist
Asus · Rt Ax55 Firmware
ASUS RT-AX55 firmware 3.0.0.4.386.51598 fails to sanitize the qos_bw_rulelist parameter on /start_apply.htm, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the router, which is a network edge device.
Description
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote command execution on an internet-facing edge device, has public exploit code, and is listed in CISA KEV with a near-term remediation deadline.
What it is
ASUS RT-AX55 firmware 3.0.0.4.386.51598 fails to sanitize the qos_bw_rulelist parameter on /start_apply.htm, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the router, which is a network edge device.
Impact
An authenticated attacker gains arbitrary OS command execution on the router, enabling full device compromise, traffic interception, and use of the router as a foothold into the internal network.
Attack surface
Reached over the network via the web management interface at /start_apply.htm; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low-privilege authentication is required and no user interaction is needed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-06-02, and public exploit write-ups are referenced; EPSS gives a 30-day exploitation probability of about 40% (98.6th percentile).
What to do
- Update ASUS RT-AX55 firmware to a version that fixes the qos_bw_rulelist command injection; if no fixed version is available, discontinue use per CISA guidance.
- Restrict access to the router web management interface to trusted management networks only; never expose it to the internet.
- Change default and weak administrative credentials and enforce strong unique passwords for router logins.
- Monitor CISA KEV guidance and apply the vendor mitigation by the 2025-06-23 due date.
Detection
- Inspect router and web server logs for POST requests to /start_apply.htm containing qos_bw_rulelist values with shell metacharacters such as ;, |, $(), or backticks.
- Monitor for unexpected outbound connections or processes spawned by the router's web management service.
- Alert on authentication to the router admin interface from unusual source addresses or at unusual times, since exploitation requires valid credentials.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-39780 to the Known Exploited Vulnerabilities catalog on 2 June 2025 as "ASUS RT-AX55 Routers OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-39780 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-39780), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.