PT-2022-26313 · Asus · Asus Nas-M25

Q. Kaiser

·

Published

2022-12-01

·

Updated

2022-12-05

·

CVE-2022-4221

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Asus NAS-M25 versions through 1.0.1.7
Description The issue is related to an improper neutralization of special elements used in an OS command, allowing an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values, specifically through cookie values.
Recommendations For Asus NAS-M25 versions through 1.0.1.7, as a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation. Avoid using unsanitized cookie values in OS commands until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-4221

Affected Products

Asus Nas-M25