CVE-2022-22054 - CERT CVE
ID CVE-2022-22054
Sažetak ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.
Reference
CVSS
Base: 3.3
Impact: 2.9
Exploitability:6.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE NONE
CVSS vektor AV:A/AC:L/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje 21-01-2022 - 13:51
Objavljeno 14-01-2022 - 05:15