CVE-2022-23970 - CERT CVE
ID CVE-2022-23970
Sažetak ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
Reference
CVSS
Base: 4.8
Impact: 4.9
Exploitability:6.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:A/AC:L/Au:N/C:N/I:P/A:P
Zadnje važnije ažuriranje 14-04-2022 - 20:42
Objavljeno 07-04-2022 - 19:15