CVE-2023-39780Active Exploitation(asus / rt-ax55)

LOWCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for asus rt-ax55 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rt-ax55
  • rt-ax55_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rt-ax55rt-ax55_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-11: 1Active Exploitation · 2026-03-11: 103-11
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    KadNap botnet exploits ASUS routers via CVE-2023-39780, then deploys custom Kademlia DHT protocol for decentralized C2 communication. Over 14,000 devices compromised by March 2026, creating resilient proxy network for cybercrime operations. #ThreatIntel #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/kadnap-botnet-2026-asus-routers

    Post summary

    The post reports that the KadNap botnet is actively exploiting ASUS routers via CVE-2023-39780, having compromised more than 14,000 devices by March 2026.

    0000067
    1.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWasusrt-ax55---
OSasusrt-ax55_firmware3.0.0.4.386.51598--

Explore more