CVE-2023-39780: ASUS RT-AX55 Routers
EPSS39.5%No. 942 of 1739 in KEV
CVE year2023~2 yrs before listing
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | ASUS |
| Product | RT-AX55 Routers |
| Name | ASUS RT-AX55 Routers OS Command Injection Vulnerability |
| Added to KEV | 2025-06-02 |
| US federal due date | 2025-06-23 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A ASUS RT-AX55 Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-02.