7.5
CVSSv2

CVE-2020-36109

Published: 01/02/2021 Updated: 05/02/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

asus rt-ax86u_firmware

Github Repositories

CVE-2020-36109 PoC causing DoS

CVE-2020-36109-POC Feb 13 2021, Altin Thartori, githubcom/tin-z Vulnerability details ASUS RT-AX86U router firmware below version under 9004_386 has a buffer overflow in the blocking_requestcgi function of the httpd module that can cause code execution when an attacker constructs malicious data The vulnerability is not only present in RT-AX86U but also in other models

PoC DoS CVE-2020-36109

CVE-2020-36109-POC Repository moved here: githubcom/sunn1day/CVE-2020-36109-POC