OS Command Injection in ASUS RT-AX55 /start_apply.htm qos_bw_rulelist
CVE-2023-39780 is an authenticated OS command injection vulnerability affecting ASUS RT-AX55 routers running firmware 3.0.0.4.386.51598. The issue is exposed through the /start_apply.htm endpoint, where the qos_bw_rulelist parameter is insufficiently sanitized, allowing an authenticated attacker to inject and execute arbitrary operating system commands on the device. The provided content consistently characterizes the flaw as a post-authentication command injection used to run arbitrary system-level commands on affected routers. The vulnerability has also been referenced by ASUS in related advisories covering similar token-module issues (CVE-2023-41345 through CVE-2023-41348).
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown (vulnerability exploited by the AyySSHush/ViciousTrap botnet; mentioned as a shared/overlapping vulnerability with the WrtHug cluster).
Major command injection vulnerability in ASUS WRT routers, reported as used in both Operation WrtHug and the earlier AyySSHush campaign.
A known Asus router vulnerability used post-compromise to run arbitrary system commands (command execution) on affected devices, enabling attackers to establish persistence (e.g., SSH access/backdoor).
An OS command injection vulnerability in ASUS RT-AX55 routers that can enable remote code execution.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.