CVE-2022-23972

HIGH

ASUS RT-AX56U Firmware - Unauthenticated SQL Injection

Title source: llm
STIX 2.1

Description

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5786-d2e86-1.html

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
asus/rt-ax56u_firmware 3.0.0.4.386.45898
Published Apr 07, 2022
Tracked Since Feb 18, 2026