CVE-2022-23971: ASUS RT-AX56U - Path Traversal
ASUS RT-AX56U’s updatePLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this ASUS RT-AX56U vulnerability?
The vulnerability ID for this ASUS RT-AX56U vulnerability is CVE-2022-23971.
What is the severity of CVE-2022-23971?
The severity of CVE-2022-23971 is high, with a CVSS score of 8.1.
How does the path traversal vulnerability in ASUS RT-AX56U's update_PLC/PORT file work?
The path traversal vulnerability in ASUS RT-AX56U's update_PLC/PORT file allows an unauthenticated LAN attacker to overwrite a system file by uploading another PLC/PORT file with the same name.
What is the impacted software version of ASUS RT-AX56U for CVE-2022-23971?
The impacted software version is Asus Rt-ax56u Firmware 3.0.0.4.386.45898.
Is the ASUS RT-AX56U device vulnerable to CVE-2022-23971?
Yes, the ASUS RT-AX56U device is vulnerable to CVE-2022-23971.