ASUS RT-AC86U - Heap-based buffer overflow
Description
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Heap-based buffer overflow in ASUS RT-AC86U configuration function allows unauthenticated LAN attacker to execute arbitrary code or disrupt service.
Vulnerability
The configuration function of ASUS RT-AC86U firmware v3.0.0.4.386.45956 contains a heap-based buffer overflow vulnerability due to insufficient validation of the decryption parameter length [1]. This allows an unauthenticated attacker on the same LAN to trigger the overflow by sending a crafted request with an overly long decryption parameter [1].
Exploitation
An attacker must be located on the local network (LAN) and does not require any authentication [1]. By sending a specially crafted request to the vulnerable configuration function, the attacker can trigger the heap-based buffer overflow [1]. No user interaction is required.
Impact
Successful exploitation enables an attacker to execute arbitrary code, perform arbitrary operations on the device, or cause a denial of service [1]. The attacker gains full control over the affected router, potentially compromising network traffic and connected devices.
Mitigation
ASUS has released firmware version 3.0.0.4_386_46092 to fix this vulnerability [1]. Users should update their RT-AC86U routers to this patched version. No workaround is provided; updating is the recommended mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5793-4f9d3-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.