CVE-2023-34360: ASUS Rt-AX88U Firmware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.

Affected products

  • ASUS Rt-AX88U Firmware: up to and including 3.0.0.4.388.23110

Published 2023-07-31. Last modified 2026-06-17.