Security Advisory

CVE-2022-4221

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-12-01 09:26:48
Last updated 2025-04-14 17:51:37
Assigner ONEKEY
State PUBLISHED

Description

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.