First published: Thu Apr 07 2022(Updated: )
ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax56u Firmware | =3.0.0.4.386.45898 | |
ASUS RT-AX56U |
Update ASUS RT-AX56U firmware version to 3.0.0.4.386.45934
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23970 is a vulnerability in ASUS RT-AX56U's update_json function that allows a LAN attacker to overwrite system files, resulting in service disruption.
CVE-2022-23970 has a severity rating of 8.1 (High).
CVE-2022-23970 is a path traversal vulnerability that occurs due to insufficient filtering of special characters in the URL parameter of ASUS RT-AX56U's update_json function.
CVE-2022-23970 affects ASUS RT-AX56U firmware version 3.0.0.4.386.45898.
To mitigate CVE-2022-23970, update your ASUS RT-AX56U firmware to a version that addresses the vulnerability.