Skip to main content

Vendor/product archive

asus / rt-ax56u_firmware CVEs

Beta · best-effort

10 CVEs tagged to asus / rt-ax56u_firmware1 Critical, 8 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2021-40556

Published Oct 6, 2022

A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "cauplo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23973

Published Apr 7, 2022

ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23972

Published Apr 7, 2022

ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23971

Published Apr 7, 2022

ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23970

Published Apr 7, 2022

ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22054

Published Jan 14, 2022

ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated lo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1