← Vulnerability feed

Vulnerability record · CVE-2023-39780 · published 11 September 2023

CVE-2023-39780: ASUS RT-AX55 Router OS Command Injection via qos_bw_rulelist

Asus · Rt Ax55 Firmware

ASUS RT-AX55 firmware 3.0.0.4.386.51598 fails to sanitize the qos_bw_rulelist parameter on /start_apply.htm, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the router, which is a network edge device.

8.8 CVSS 3.1 High CISA KEV since 2 Jun 2025 EPSS 40% · top 1.4% CWE-78 · OS command injection
8.8CVSS 3.1 base score
40%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
14References, 13 tagged exploit
17 Jun 2026Last modified by NVD

Description

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote command execution on an internet-facing edge device, has public exploit code, and is listed in CISA KEV with a near-term remediation deadline.

What it is

ASUS RT-AX55 firmware 3.0.0.4.386.51598 fails to sanitize the qos_bw_rulelist parameter on /start_apply.htm, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary commands on the router, which is a network edge device.

Impact

An authenticated attacker gains arbitrary OS command execution on the router, enabling full device compromise, traffic interception, and use of the router as a foothold into the internal network.

Attack surface

Reached over the network via the web management interface at /start_apply.htm; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low-privilege authentication is required and no user interaction is needed.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-06-02, and public exploit write-ups are referenced; EPSS gives a 30-day exploitation probability of about 40% (98.6th percentile).

What to do

  • Update ASUS RT-AX55 firmware to a version that fixes the qos_bw_rulelist command injection; if no fixed version is available, discontinue use per CISA guidance.
  • Restrict access to the router web management interface to trusted management networks only; never expose it to the internet.
  • Change default and weak administrative credentials and enforce strong unique passwords for router logins.
  • Monitor CISA KEV guidance and apply the vendor mitigation by the 2025-06-23 due date.

Detection

  • Inspect router and web server logs for POST requests to /start_apply.htm containing qos_bw_rulelist values with shell metacharacters such as ;, |, $(), or backticks.
  • Monitor for unexpected outbound connections or processes spawned by the router's web management service.
  • Alert on authentication to the router admin interface from unusual source addresses or at unusual times, since exploitation requires valid credentials.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-39780 to the Known Exploited Vulnerabilities catalog on 2 June 2025 as "ASUS RT-AX55 Routers OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-39780 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26376Asuswrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…EPSS 1.3%9.8CVE-2021-41435Asus gt-ax11000 firmware improper restriction of authentication attempts vulnerabilityA brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, …EPSS 6.5%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.8CVE-2023-41345Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module.…EPSS 1.3%8.8CVE-2023-41346Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. A…EPSS 1.2%8.8CVE-2023-41347Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An …EPSS 1.3%8.8CVE-2023-41348Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication mod…EPSS 1.3%7.5CVE-2021-41436Asus gt-ax11000 firmware http request smuggling vulnerabilityAn HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U …EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2023-39780), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.