go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS RT-AC86U - Command Injection

TVN ID TVN-202202007
CVE ID CVE-2022-25597
CVSS 8.8 (High)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ASUS RT-AC86U firmware v3.0.0.4.386.45956
Description ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.
Solution Update ASUS RT-AC86U firmware version to 3.0.0.4_386_46092
Credit TianHe
Public Date 2022-03-07
Top