CVE-2023-34358: ASUS Rt-AX88U Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS condition.

Affected products

  • ASUS Rt-AX88U Firmware: before 3.0.0.4.388.23748 (fixed in 3.0.0.4.388.23748)

Published 2023-07-31. Last modified 2026-06-17.