CVE Published: 07/04/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: twcert |
Vendor: ASUS |
Product: RT-AX56U Status : PUBLISHED
CVE-2022-23972 Description
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H