NA

CVE-2023-26602

Published: 26/02/2023 Updated: 07/03/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

ASUS ASMB8 iKVM firmware up to and including 1.14.51 allows remote malicious users to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

asus asmb8-ikvm firmware

Exploits

ASUS ASMB8 iKVM firmware versions 11451 and below suffers from a flaw where SNMPv2 can be used with write access to introduce arbitrary extensions to achieve remote code execution as root The researchers also discovered a hardcoded administrative account ...

Github Repositories

Exploit information for CVE-2023-26602

Exploit information for CVE-2023-26602 DISCLAIMER: For education, research, ethical hacking and professional pentesting ONLY