CVE-2023-39780: listed in the CISA KEV catalog

CVE-2023-39780 · CVSS 8.8 HIGH · EPSS 34% · KEV 2025-06-02

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

Is CVE-2023-39780 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2023-39780

PlainSec has not published a story about this CVE.

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.