ZeroHour

CVE-2022-25597

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

Vendors
asus
Products
rt-ac86u firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.