CVE Published: 07/04/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: twcert |
Vendor: ASUS |
Product: RT-AC86U Status : PUBLISHED
CVE-2022-25596 Description
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H