ASUS RT-AX56U - Path Traversal
Vulnerability Description
ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23971
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- hanpeng (Cyber Kunlun Lab)
More from ASUS
View All →Affected Vendor
ASUS
View all reports →