Show filters
104 Total Results
Displaying 31-40 of 104
Sort by:
Attacker Value
Unknown
CVE-2022-23970
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
0
Attacker Value
Unknown
CVE-2022-23973
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.
0
Attacker Value
Unknown
CVE-2022-23972
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
0
Attacker Value
Unknown
CVE-2022-23971
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.
0
Attacker Value
Unknown
CVE-2022-23437
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
0
Attacker Value
Unknown
CVE-2022-22054
Disclosure Date: January 14, 2022 (last updated February 23, 2025)
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.
0
Attacker Value
Unknown
CVE-2021-46109
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.
0
Attacker Value
Unknown
CVE-2021-44158
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.
0
Attacker Value
Unknown
CVE-2019-20082
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.
0
Attacker Value
Unknown
CVE-2021-36374
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
0