Rt Ax55
Vendor:
First CVE: Apr 12, 2021 · Active for 5 years
14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Rt Ax55 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2021
5 years ago
Most Recent CVE
Nov 3, 2023
997 days ago
CVE Severity & Scoring
Rt Ax5514 CVEs
71%
21%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low6 (42.9%)
High3 (21.4%)
None5 (35.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39780HIGH On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token | Sep 11, 2023 | 8.8 | 82 | YES | NO |
CVE-2021-41435CRITICAL A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX8 | Nov 19, 2021 | 9.8 | 35 | NO | NO |
CVE-2022-26376CRITICAL A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted H | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-43702CRITICAL ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change | Jul 5, 2022 | 9.0 | 29 | NO | NO |
CVE-2021-41436HIGH An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series( | Nov 19, 2021 | 7.5 | 28 | NO | NO |
CVE-2023-41345HIGH ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attack | Nov 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41348HIGH ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote at | Nov 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-39240HIGH
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its | Sep 7, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-39239HIGH
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its appl | Sep 7, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-41347HIGH ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker c | Nov 3, 2023 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Rt Ax55
Top CWEs
Versions
No cataloged versions.