VYPR
Unrated severityNVD Advisory· Published Nov 3, 2023· Updated Sep 6, 2024

ASUS RT-AX55 - command injection - 4

CVE-2023-41348

Description

ASUS RT-AX55 firmware 3.0.0.4.51598 contains a command injection vulnerability in authentication code verification, allowing authenticated remote attackers to execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ASUS RT-AX55 firmware 3.0.0.4.51598 contains a command injection vulnerability in authentication code verification, allowing authenticated remote attackers to execute arbitrary commands.

Vulnerability

ASUS RT-AX55 router firmware version 3.0.0.4.51598 has a command injection vulnerability in its authentication-related code-authentication module. The module fails to properly filter special characters in user-supplied parameters. This affects the confirm-verification-code functionality, enabling injection of arbitrary operating system commands. The vulnerability is present in firmware 3.0.0.4.51598 and earlier versions [1].

Exploitation

An attacker must have network access to the router and valid authentication credentials (e.g., administrator password). No user interaction is required beyond authentication. The attacker sends a specially crafted request to the authentication verification endpoint, injecting shell metacharacters into the parameter that is not sanitized. The injected commands are then executed by the underlying system [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the affected router with root privileges. This can lead to full compromise of confidentiality, integrity, and availability: the attacker can read sensitive data, modify device configuration, install persistent backdoors, disrupt networking services, or completely terminate system operation [1].

Mitigation

The vendor released a fixed firmware version 3.0.0.4.386_51948 on 2023-11-03 to address this vulnerability. Users should update their RT-AX55 routers to this version or later through the device's administration interface. No workaround is available for older firmware [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asus/RT-AX55llm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 3.0.0.4.386.51598

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.