ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28888 | ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database. |
Fixes
Solution
Update ASUS RT-AX56U firmware version to 3.0.0.4.386.45934
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5786-d2e86-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T19:30:39.747Z
Reserved: 2022-01-26T00:00:00
Link: CVE-2022-23972
No data.
Status : Modified
Published: 2022-04-07T19:15:08.593
Modified: 2024-11-21T06:49:32.910
Link: CVE-2022-23972
No data.
OpenCVE Enrichment
No data.
EUVD