Back to Database
Status published
High
CVE-2023-34359
ASUS RT-AX88U - Out-of-bounds Read - 2
Vulnerability Description
ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-34359
Credits & Attribution
No credits recorded in the NVD database.
More from ASUS
View All →CVE-2025-9968
A link following vulnerability exists in the UnifyScanner component of...
High
8.5
CVE-2025-9338
A improper restriction of operations within the bounds of a...
High
7.3
CVE-2025-9337
A null pointer dereference has been identified in the AsIO3.sys...
Medium
6.8
CVE-2025-9336
A stack buffer overflow has been identified in the AsIO3.sys...
Medium
6.8
CVE-2025-6398
A null pointer dereference vulnerability exists in the IOMap64.sys driver...
Medium
6.7
Affected Vendor
ASUS
View all reports →Affected Software
RT-AX88U
Vulnerable Versions:
Timeline
Official Publish:
July 31st, 2023
Last Modified:
October 21st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H