VYPR
Unrated severityNVD Advisory· Published Apr 7, 2022· Updated Sep 17, 2024

ASUS RT-AX56U - Path Traversal

CVE-2022-23970

Description

ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ASUS RT-AX56U firmware suffers a path traversal in the update_json function, allowing an unauthenticated LAN attacker to overwrite system files and cause service disruption.

Vulnerability

The vulnerability exists in the update_json function of ASUS RT-AX56U firmware versions prior to 3.0.0.4.386.45934. The function does not sufficiently filter special characters in a URL parameter, leading to a path traversal condition [1]. The affected product is ASUS RT-AX56U firmware version 3.0.0.4.386.45898 [1]. The attacker can upload a crafted JSON file, which may overwrite a system file with the same file name [1].

Exploitation

An unauthenticated attacker on the same LAN can exploit this vulnerability without any authentication required [1]. The attacker must be able to reach the update_json endpoint and supply a URL parameter containing path traversal sequences (e.g., ../). The concrete sequence involves uploading a specially crafted JSON file that, due to the insufficient path sanitization, is written to an arbitrary system directory [1]. No user interaction is needed [1].

Impact

Successful exploitation allows an attacker to overwrite an arbitrary system file, which can lead to service disruption [1]. The CVSS vector indicates high impact to integrity and availability, but no direct impact to confidentiality (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) [1]. The attacker gains the ability to disrupt router services, potentially making the device unstable or inoperable [1].

Mitigation

The vulnerability is fixed in firmware version 3.0.0.4.386.45934, released on an undisclosed date before the publication of this CVE [1]. Users should update their ASUS RT-AX56U router to this firmware version or later [1]. No workarounds are mentioned in the reference [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asus/RT-AX56U V2llm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 3.0.0.4.386.45898

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.