HIGH
ASUS RT-AX56U - SQL Injection
Published Apr 7, 2022
8.8
HIGHCVSS 3.1
EPSS 0.54%
Description
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
Affected products
-
- Version 3.0.0.4.386.45898StatusaffectedConstraints-
- Version
AND
- 3.0.0.4.386.45898
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update ASUS RT-AX56U firmware version to 3.0.0.4.386.45934
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28888 Advisory
- https://www.twcert.org.tw/tw/cp-132-5786-d2e86-1.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28888 | Advisory | |
| https://www.twcert.org.tw/tw/cp-132-5786-d2e86-1.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Apr 7, 2022
Updated Sep 16, 2024
Reserved Jan 26, 2022
Link CVE-2022-23972
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-28888 Assigner twcert
Published Apr 7, 2022
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2022-28888