Security Advisory
CVE-2022-4221
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.