ASUS RT-AX56U - Path Traversal
Description
ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ASUS RT-AX56U firmware suffers a path traversal in the update_json function, allowing an unauthenticated LAN attacker to overwrite system files and cause service disruption.
Vulnerability
The vulnerability exists in the update_json function of ASUS RT-AX56U firmware versions prior to 3.0.0.4.386.45934. The function does not sufficiently filter special characters in a URL parameter, leading to a path traversal condition [1]. The affected product is ASUS RT-AX56U firmware version 3.0.0.4.386.45898 [1]. The attacker can upload a crafted JSON file, which may overwrite a system file with the same file name [1].
Exploitation
An unauthenticated attacker on the same LAN can exploit this vulnerability without any authentication required [1]. The attacker must be able to reach the update_json endpoint and supply a URL parameter containing path traversal sequences (e.g., ../). The concrete sequence involves uploading a specially crafted JSON file that, due to the insufficient path sanitization, is written to an arbitrary system directory [1]. No user interaction is needed [1].
Impact
Successful exploitation allows an attacker to overwrite an arbitrary system file, which can lead to service disruption [1]. The CVSS vector indicates high impact to integrity and availability, but no direct impact to confidentiality (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) [1]. The attacker gains the ability to disrupt router services, potentially making the device unstable or inoperable [1].
Mitigation
The vulnerability is fixed in firmware version 3.0.0.4.386.45934, released on an undisclosed date before the publication of this CVE [1]. Users should update their ASUS RT-AX56U router to this firmware version or later [1]. No workarounds are mentioned in the reference [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 3.0.0.4.386.45898
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5784-68aa3-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.