CVE-2023-39780

Confirmed PUBLISHED

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist...

ASUS · RT-AX55

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High EPSS 32.2%

At a Glance

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

cisa edge
CVE Published
Sep 11, 2023
Exploitation Reported
Jun 01, 2026
CVSS
8.8 High
EPSS
32.2%
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
asus
rt-ax55

3.0.0.4.386.51598

Affected
ASUS
RT-AX55

3.0.0.4.386.51598

Affected

CVE References

  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.md
  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.md
  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.md
  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.md
  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.md
Show 1 more reference
  • GitHub — D2y6p/CVE github.com · CVE Record https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.md

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.