CVE-2023-34359: ASUS Rt-AX88U Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.

Affected products

  • ASUS Rt-AX88U Firmware: before 3.0.0.4.388.23748 (fixed in 3.0.0.4.388.23748)

Published 2023-07-31. Last modified 2026-06-17.