Back

HIGH

ASUS RT-AX56U - Path Traversal

Published Apr 7, 2022

Description

ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.

Affected products

Remediation

Vendor solution

Update ASUS RT-AX56U firmware version to 3.0.0.4.386.45934

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Apr 7, 2022
Updated Sep 17, 2024
Reserved Jan 26, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a