VYPR
Unrated severityNVD Advisory· Published Nov 3, 2023· Updated Sep 4, 2024

ASUS RT-AX55 - command injection - 3

CVE-2023-41347

Description

ASUS RT-AX55's check token module lacks input filtering, allowing authenticated remote attackers to inject commands, execute arbitrary code, or disrupt the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ASUS RT-AX55's check token module lacks input filtering, allowing authenticated remote attackers to inject commands, execute arbitrary code, or disrupt the system.

Vulnerability

A command injection vulnerability exists in the authentication-related check token module of the ASUS RT-AX55 router running firmware versions up to 3.0.0.4.386.51598 [1]. The module fails to properly filter special characters in input parameters, thereby enabling an authenticated remote attacker to inject arbitrary operating system commands [1].

Exploitation

An attacker must first obtain valid authentication credentials for the router's management interface [1]. With network access to the administration web panel, the attacker crafts a request to the check token endpoint that includes specially crafted input containing command separators and shell metacharacters [1]. The injected commands are then executed on the device with the privileges of the affected service [1].

Impact

Successful exploitation results in arbitrary command execution on the ASUS RT-AX55 router [1]. An attacker can execute system commands, disrupt device operations, terminate services, and potentially gain full control of the affected device, leading to a complete compromise of confidentiality, integrity, and availability (CVSS 8.8, High) [1].

Mitigation

ASUS released fixed firmware version 3.0.0.4.386_51948 to address this vulnerability [1]. Users should update their RT-AX55 devices to this version immediately. No workarounds are published. The device is not listed on CISA's Known Exploited Vulnerabilities Catalog at the time of this writing.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asus/RT-AX55llm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 3.0.0.4.386.51598

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.