Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-23970
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
0
Attacker Value
Unknown
CVE-2022-23973
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.
0
Attacker Value
Unknown
CVE-2022-23972
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
0
Attacker Value
Unknown
CVE-2022-23971
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.
0