go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS RT-AC86U - Heap-based buffer overflow

TVN ID TVN-202202006
CVE ID CVE-2022-25596
CVSS 8.8 (High)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ASUS RT-AC86U firmware v3.0.0.4.386.45956
Description ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
Solution Update ASUS RT-AC86U firmware version to 3.0.0.4_386_46092
Credit TianHe
Public Date 2022-03-07
Top