CVE-2020-36109: ASUS Rt-AX86U Firmware

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

Affected products

  • ASUS Rt-AX86U Firmware: before 9.0.0.4_386 (fixed in 9.0.0.4_386)

Published 2021-02-01. Last modified 2026-06-17.