ASUS RT-AX56U - Path Traversal
Description
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated path traversal in ASUS RT-AX56U login lets LAN attackers download arbitrary files.
Vulnerability
CVE-2022-22054 is a path traversal vulnerability in the login function of the ASUS RT-AX56U router. The URL parameters of the login page do not adequately filter special characters, allowing an attacker to traverse directories. The affected firmware version is 3.0.0.4.386.44266 (as per the advisory). [1]
Exploitation
An unauthenticated attacker with access to the local area network can send crafted HTTP requests to the login endpoint. By injecting path traversal sequences (such as ../) in URL parameters, the attacker can navigate to restricted system paths. No authentication is needed, and no user interaction is required. [1]
Impact
Successful exploitation allows the attacker to download arbitrary files from the router's filesystem. This is a confidentiality impact, as the attacker can read sensitive files such as configuration files or credentials. The CVSS score is 6.5 (Medium) with the vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. [1]
Mitigation
ASUS was contacted for a firmware update; the advisory states to contact ASUS for version updates. No fixed version is explicitly listed in the reference. The user should apply the latest firmware available from ASUS. If no patch is available, network segmentation and restricting LAN access may reduce risk. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 3.0.0.4.386.44266
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5508-59251-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.