516
VMScore

CVE-2022-25597

Published: 07/04/2022 Updated: 23/06/2023
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN malicious user to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

asus rt-ac86u_firmware 3.0.0.4.386.45956