ASUS RT-AC86U - Improper Input Validation
Description
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated LAN attacker can cause denial of service on ASUS RT-AC86U router by sending a specially crafted request.
Vulnerability
The ASUS RT-AC86U router firmware version 3.0.0.4.386.45956 contains an improper input validation vulnerability in handling user requests. An unauthenticated attacker on the local network can send a particular request that triggers a server-to-client reply attempt which leads to a denial of service. The issue is fixed in firmware version 3.0.0.4_386_46092. [1]
Exploitation
An attacker must be on the same LAN as the affected router. No authentication is required. The attacker establishes a connection with the router and sends a specific crafted message. Due to improper handling, the router attempts to reply but fails, causing a service interruption. No user interaction is needed. [1]
Impact
Successful exploitation results in a denial of service (DoS) condition, rendering the router unavailable. The CVSS score is 6.5 (Medium) with vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating high availability impact but no confidentiality or integrity impact. [1]
Mitigation
The vendor has released a fix in firmware version 3.0.0.4_386_46092. Users should update their ASUS RT-AC86U firmware to this version or later. No workarounds are mentioned in the reference. The issue was publicly disclosed on 2022-03-07. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5792-3f3f5-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.