CVE-2022-4221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/12/2022
Last modified:
07/11/2023

Description

Improper Neutralization of Special Elements used in an OS Command (&amp;#39;OS Command Injection&amp;#39;) vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:nas-m25_firmware:*:*:*:*:*:*:*:* 1.0.1.7 (including)
cpe:2.3:h:asus:nas-m25:-:*:*:*:*:*:*:*