VendorsASUSrt-ax88u_firmwareany version
Vulnerabilities

ASUS RT-AX88U any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-41435
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Published 2021-11-19 · Modified
10.0EPSS 0.065
CVE-2022-26674
ASUS RT-AX88U - Format String
Published 2022-04-22 · Modified
9.8EPSS 0.028
CVE-2023-41349
ASUS RT-AX88U - externally-controlled format string
Published 2023-09-18 · Modified
8.8EPSS 0.009
CVE-2023-34360
ASUS RT-AX88U - Stored XSS
Published 2023-07-31 · Modified
8.2EPSS 0.005
CVE-2021-41436
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.
Published 2021-11-19 · Modified
7.8EPSS 0.050
CVE-2021-3128
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.
Published 2021-04-12 · Modified
7.5EPSS 0.022
CVE-2023-34358
ASUS RT-AX88U - Out-of-bounds Read - 1
Published 2023-07-31 · Modified
7.5EPSS 0.008
CVE-2023-34359
ASUS RT-AX88U - Out-of-bounds Read - 2
Published 2023-07-31 · Modified
7.5EPSS 0.008
CVE-2021-41437
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
Published 2022-09-26 · Modified
6.5EPSS 0.011
CVE-2022-26673
ASUS RT-AX88U - Stored XSS
Published 2022-04-22 · Modified
5.4EPSS 0.006