CVE-2022-23972

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
07/04/2022
Last modified:
14/04/2022

Description

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-ax56u_firmware:3.0.0.4.386.45898:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax56u:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools