ASUS Routers Are Vulnerable!

ASUS Routers Are Vulnerable!

ASUS Vulnerable

Recent discoveries have shed light on three critical remote code execution vulnerabilities that directly impact ASUS RT-AX55, RT-AX56U_V2, and RT-AC86U routers. Notably, these high-performance WiFi routers are popular among gamers and individuals requiring robust connectivity in their daily lives. Alarmingly, these vulnerabilities each score a 9.8 out of 10 on the CVSS v3.1 scale, indicating their severity. Format string weaknesses, service disruptions, and random device functions are associated with these flaws, which can be exploited via attacks aimed at specific administrative API functions on the routers.

To address these risks, ASUS has released firmware updates for all affected models. It is imperative for users to stay up to date with security updates and promptly install patches to counter threats related to remote code execution, unauthorized access, and compromised system integrity.

Detailed Insights into the Vulnerabilities and Their Impacts

The Taiwanese CERT unveiled three vulnerabilities that have serious implications for affected users. These include:

– CVE-2023-39238: Affects the iperf-related API module ‘ser_iperf3_svr.cgi’.
– CVE-2023-39239: Targets the general setting function’s API.
– CVE-2023-39240: Pertains to the iperf-related API module ‘ser_iperf3_cli.cgi’.

Unsuspecting users are at a heightened risk as remote attackers can exploit these vulnerabilities to execute arbitrary commands on impacted devices. Thus, organizations should prioritize the application of necessary security patches to prevent potential exploitation and secure their systems.

Impacted Firmware Versions and Recommended Actions

These issues specifically affect certain firmware versions on ASUS RT-AX55, RT-AX56U_V2, and RT-AC86U routers. Consequently, devices may be vulnerable to various security hazards, jeopardizing user data and privacy. To uphold security and protection against potential threats, users should promptly update the firmware on these routers.

In response, ASUS released patches for each affected router model – August 2023 for RT-AX55, May 2023 for AX56U_V2, and July 2023 for RT-AC86U, significantly bolstering the security measures on these devices and mitigating the risk of cyberattacks and unauthorized access. It is strongly advised that users update their firmware as soon as possible to maintain optimum protection for their networks.

Importance of Timely Security Updates

For users who have yet to install the latest security updates, doing so should be a top priority. By staying up to date with the latest patches, users significantly reduce the risk of potential cyber threats and data breaches. Regular firmware checks and installations are essential for maximum device protection and optimal functionality.

Additional Recommendations for Consumer Router Security

To further minimize risks associated with consumer router vulnerabilities, experts suggest disabling the remote administration (WAN Web Access) feature. While this functionality enables router control via the internet, it poses increased risks as cybercriminals may gain access and compromise entire home networks. As an alternative, managing router settings through a direct connection ensures a secure environment and prevents unauthorized access.

Frequently Asked Questions (FAQ)

1. What are the impacted ASUS routers and their vulnerabilities?

The impacted routers include ASUS RT-AX55, RT-AX56U_V2, and RT-AC86U models. They have three critical remote code execution vulnerabilities with a CVSS v3.1 severity score of 9.8 out of 10. These vulnerabilities can be exploited by attackers targeting specific administrative API functions on the routers.

2. What are the vulnerability ID numbers and affected modules?

– CVE-2023-39238 affecting the iperf-related API module ‘ser_iperf3_svr.cgi’.
– CVE-2023-39239 attacking the general setting function’s API.
– CVE-2023-39240 related to the iperf-related API module ‘ser_iperf3_cli.cgi’.

3. What are the consequences of these vulnerabilities?

Remote attackers can exploit these vulnerabilities to execute arbitrary commands on impacted devices, compromising user data and privacy. Organizations are advised to apply security patches promptly to prevent exploitation and secure their systems.

4. What actions do users need to take to protect their routers?

Users should update the firmware on their routers to the latest security updates released by ASUS. These patches help mitigate risks associated with cyberattacks and unauthorized access. The patches were released in August 2023 for RT-AX55, May 2023 for AX56U_V2, and July 2023 for RT-AC86U.

5. What are additional recommendations for consumer router security?

Experts recommend disabling the remote administration (WAN Web Access) feature to minimize risks associated with consumer router vulnerabilities. Users should manage router settings through a direct connection to ensure a secure environment and prevent unauthorized access.

First Reported on: bleepingcomputer.com
Featured Image Credit: Photo by Stephen Phillips – Hostreviews.co.uk; Unsplash; Thank you!

Lila Anderson

Lila Anderson

Lila is a skilled SaaS writer who combines her love for technology and storytelling to create compelling content. With her words, she navigates the complex world of software-as-a-service, making it accessible and engaging for readers. Fun fact: Lila owns a hot air balloon company.
Share the Post:
Poland Energy Future

Westinghouse Builds Polish Power Plant

Westinghouse Electric Company and Bechtel have come together to establish a formal partnership in order to design and construct Poland’s inaugural nuclear power plant at

EV Labor Market

EV Industry Hurting For Skilled Labor

The United Auto Workers strike has highlighted the anticipated change towards a future dominated by electric vehicles (EVs), a shift which numerous people think will

Soaring EV Quotas

Soaring EV Quotas Spark Battle Against Time

Automakers are still expected to meet stringent electric vehicle (EV) sales quotas, despite the delayed ban on new petrol and diesel cars. Starting January 2023,

Affordable Electric Revolution

Tesla Rivals Make Bold Moves

Tesla, a name synonymous with EVs, has consistently been at the forefront of the automotive industry’s electric revolution. The products that Elon Musk has developed

Poland Energy Future

Westinghouse Builds Polish Power Plant

Westinghouse Electric Company and Bechtel have come together to establish a formal partnership in order to design and construct Poland’s inaugural nuclear power plant at the Lubiatowo-Kopalino site in Pomerania.

EV Labor Market

EV Industry Hurting For Skilled Labor

The United Auto Workers strike has highlighted the anticipated change towards a future dominated by electric vehicles (EVs), a shift which numerous people think will result in job losses. However,

Soaring EV Quotas

Soaring EV Quotas Spark Battle Against Time

Automakers are still expected to meet stringent electric vehicle (EV) sales quotas, despite the delayed ban on new petrol and diesel cars. Starting January 2023, more than one-fifth of automobiles

Affordable Electric Revolution

Tesla Rivals Make Bold Moves

Tesla, a name synonymous with EVs, has consistently been at the forefront of the automotive industry’s electric revolution. The products that Elon Musk has developed are at the forefront because

Sunsets' Technique

Inside the Climate Battle: Make Sunsets’ Technique

On February 12, 2023, Luke Iseman and Andrew Song from the solar geoengineering firm Make Sunsets showcased their technique for injecting sulfur dioxide (SO₂) into the stratosphere as a means

AI Adherence Prediction

AI Algorithm Predicts Treatment Adherence

Swoop, a prominent consumer health data company, has unveiled a cutting-edge algorithm capable of predicting adherence to treatment in people with Multiple Sclerosis (MS) and other health conditions. Utilizing artificial

Personalized UX

Here’s Why You Need to Use JavaScript and Cookies

In today’s increasingly digital world, websites often rely on JavaScript and cookies to provide users with a more seamless and personalized browsing experience. These key components allow websites to display

Geoengineering Methods

Scientists Dimming the Sun: It’s a Good Thing

Scientists at the University of Bern have been exploring geoengineering methods that could potentially slow down the melting of the West Antarctic ice sheet by reducing sunlight exposure. Among these

why startups succeed

The Top Reasons Why Startups Succeed

Everyone hears the stories. Apple was started in a garage. Musk slept in a rented office space while he was creating PayPal with his brother. Facebook was coded by a

Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as opposed to the 176% return

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024 approaches, the industry seems to

Elevated Content Deals

Elevate Your Content Creation with Amazing Deals

The latest Tech Deals cater to creators of different levels and budgets, featuring a variety of computer accessories and tools designed specifically for content creation. Enhance your technological setup with

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security. These carefully designed learning courses

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers to better manage smaller unmanned

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like artificial intelligence (AI), semiconductors, and

Huge Savings

Score Massive Savings on Portable Gaming

This week in tech bargains, a well-known firm has considerably reduced the price of its portable gaming device, cutting costs by as much as 20 percent, which matches the lowest

Cloudfare Protection

Unbreakable: Cloudflare One Data Protection Suite

Recently, Cloudflare introduced its One Data Protection Suite, an extensive collection of sophisticated security tools designed to protect data in various environments, including web, private, and SaaS applications. The suite

Drone Revolution

Cool Drone Tech Unveiled at London Event

At the DSEI defense event in London, Israeli defense firms exhibited cutting-edge drone technology featuring vertical-takeoff-and-landing (VTOL) abilities while launching two innovative systems that have already been acquired by clients.

2D Semiconductor Revolution

Disrupting Electronics with 2D Semiconductors

The rapid development in electronic devices has created an increasing demand for advanced semiconductors. While silicon has traditionally been the go-to material for such applications, it suffers from certain limitations.

Cisco Growth

Cisco Cuts Jobs To Optimize Growth

Tech giant Cisco Systems Inc. recently unveiled plans to reduce its workforce in two Californian cities, with the goal of optimizing the company’s cost structure. The company has decided to

FAA Authorization

FAA Approves Drone Deliveries

In a significant development for the US drone industry, drone delivery company Zipline has gained Federal Aviation Administration (FAA) authorization, permitting them to operate drones beyond the visual line of

Mortgage Rate Challenges

Prop-Tech Firms Face Mortgage Rate Challenges

The surge in mortgage rates and a subsequent decrease in home buying have presented challenges for prop-tech firms like Divvy Homes, a rent-to-own start-up company. With a previous valuation of

Lighthouse Updates

Microsoft 365 Lighthouse: Powerful Updates

Microsoft has introduced a new update to Microsoft 365 Lighthouse, which includes support for alerts and notifications. This update is designed to give Managed Service Providers (MSPs) increased control and

Website Lock

Mysterious Website Blockage Sparks Concern

Recently, visitors of a well-known resource website encountered a message blocking their access, resulting in disappointment and frustration among its users. While the reason for this limitation remains uncertain, specialists