Junglewise Threat Intelligence

CVE-2023-39780: ASUS RT-AX55 OS command injection in start_apply.htm

CVE-2023-39780 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-06-02

Vendors: ASUS.

Executive brief

ASUS RT-AX55 wireless routers are affected by a security flaw that allows an authorized user to take complete control of the device. By sending specially crafted data to the router's management interface, an attacker can execute system-level commands. This could lead to the interception of internet traffic, unauthorized access to the local network, or a total disruption of internet services.

Technical details

An OS command injection vulnerability (CWE-78) exists in ASUS RT-AX55 routers running firmware version 3.0.0.4.386.51598. The flaw is located in the '/start_apply.htm' endpoint via the 'qos_bw_rulelist' parameter, which fails to properly sanitize user input before passing it to a system shell. A remote attacker with low-privileged authentication can exploit this to execute arbitrary commands with elevated privileges on the underlying Linux operating system. This vulnerability has been observed in the wild as part of stealthy backdoor campaigns. Users are advised to update to the latest firmware version provided by ASUS.

Affected products

  • ASUS RT-AX55 3.0.0.4.386.51598

Timeline

  • 2023-09-14: disclosed: Initial NVD analysis published
  • 2025-06-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-06-02: exploited: Confirmed active exploitation in the wild