Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
2022-12-01T10:15:09.863
2024-11-21T07:34:49.130
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | nas-m25_firmware | ≤ 1.0.1.7 | Yes |
Hardware | asus | nas-m25 | - | No |