CVE Vulnerabilities

CVE-2022-25597

Published: Apr 07, 2022 | Modified: Jun 23, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

Affected Software

Name Vendor Start Version End Version
Rt-ac86u_firmware Asus 3.0.0.4.386.45956 (including) 3.0.0.4.386.45956 (including)

References