Back

HIGH

ASUS RT-AX56U - SQL Injection

Published Apr 7, 2022

Description

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

Affected products

Remediation

Vendor solution

Update ASUS RT-AX56U firmware version to 3.0.0.4.386.45934

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Apr 7, 2022
Updated Sep 16, 2024
Reserved Jan 26, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Apr 7, 2022
Updated Sep 16, 2024
Exploited since n/a
EUVD-2022-28888