CVE-2022-23972
HIGHASUS RT-AX56U Firmware - Unauthenticated SQL Injection
Title source: llmDescription
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5786-d2e86-1.html
Scores
CVSS v3
8.8
EPSS
0.0006
EPSS Percentile
19.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
asus/rt-ax56u_firmware
3.0.0.4.386.45898
Published
Apr 07, 2022
Tracked Since
Feb 18, 2026