ZeroHour

CVE-2022-23972

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
Description

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

Vendors
asus
Products
rt-ax56u firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.