Vulnerabilities > CVE-2022-25597 - Unspecified vulnerability in Asus Rt-Ac86U Firmware 3.0.0.4.386.45956

047910
CVSS 8.8 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
asus

Summary

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

Vulnerable Configurations

Part Description Count
OS
Asus
1
Hardware
Asus
1