Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 23, 2025

CVE-2023-39780

High
EPSS 42.7%CISA KEV
ASUS/RT-AX55 Routers

Description

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.

EPSS — Exploit Probability

42.7%

Higher than 97.4% of all CVEs

Required Action

https://www.asus.com/networking-iot-servers/wifi-6/all-series/rt-ax55/helpdesk_bios/?model2Name=RT-AX55 ; https://www.asus.com/content/asus-product-security-advisory/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-39780

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
42.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jun 2, 2025

Added to KEV

Jun 2, 2025

Remediation Due

Jun 23, 2025

Affected Product

ASUS

RT-AX55 Routers

View all ASUS CVEs