CVE-2022-23970: ASUS RT-AX56U - Path Traversal
ASUS RT-AX56U’s updatejson function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-23970?
CVE-2022-23970 is a vulnerability in ASUS RT-AX56U's update_json function that allows a LAN attacker to overwrite system files, resulting in service disruption.
What is the severity of CVE-2022-23970?
CVE-2022-23970 has a severity rating of 8.1 (High).
How does CVE-2022-23970 work?
CVE-2022-23970 is a path traversal vulnerability that occurs due to insufficient filtering of special characters in the URL parameter of ASUS RT-AX56U's update_json function.
What software versions are affected by CVE-2022-23970?
CVE-2022-23970 affects ASUS RT-AX56U firmware version 3.0.0.4.386.45898.
How can I mitigate CVE-2022-23970?
To mitigate CVE-2022-23970, update your ASUS RT-AX56U firmware to a version that addresses the vulnerability.