Vulnerability Details CVE-2022-23972
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 5.8
Products affected by CVE-2022-23972
-
cpe:2.3:h:asus:rt-ax56u:-
-
cpe:2.3:o:asus:rt-ax56u_firmware:3.0.0.4.386.45898