VendorsASUSrt-ax56uall versions
Vulnerabilities

ASUS RT-AX56U

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2021-41435
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Published 2021-11-19 · Modified
10.0EPSS 0.065
CVE-2018-20334
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Published 2020-03-20 · Modified
10.0EPSS 0.039
CVE-2022-26376
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Published 2022-08-05 · Modified
9.8EPSS 0.013
CVE-2021-43702
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
Published 2022-07-05 · Modified
9.0EPSS 0.010
CVE-2021-40556
A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability allows an attacker to execute commands remotely. The vulnerability requires authentication.
Published 2022-10-06 · Modified
8.8EPSS 0.014
CVE-2022-23973
ASUS RT-AX56U - Stack overflew
Published 2022-04-07 · Modified
8.8EPSS 0.006
CVE-2022-23972
ASUS RT-AX56U - SQL Injection
Published 2022-04-07 · Modified
8.8EPSS 0.005
CVE-2022-23970
ASUS RT-AX56U - Path Traversal
Published 2022-04-07 · Modified
8.1EPSS 0.005
CVE-2022-23971
ASUS RT-AX56U - Path Traversal
Published 2022-04-07 · Modified
8.1EPSS 0.005
CVE-2021-44158
ASUS RT-AX56U Router - Stack-based buffer overflow
Published 2022-01-03 · Modified
8.0EPSS 0.007
CVE-2021-41436
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.
Published 2021-11-19 · Modified
7.8EPSS 0.050
CVE-2018-20335
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
Published 2020-03-20 · Modified
7.8EPSS 0.014
CVE-2021-3128
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.
Published 2021-04-12 · Modified
7.5EPSS 0.022
CVE-2018-20333
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Published 2020-03-20 · Modified
7.5EPSS 0.012
CVE-2022-22054
ASUS RT-AX56U - Path Traversal
Published 2022-01-14 · Modified
6.5EPSS 0.005