← Back to browse · API

CVE-2022-4221

Severity
CRITICAL
CVSS
9.8
EPSS
0.04803
Risk score
40.88
CISA KEV
No
PoC
No
Published
2022-12-01
Modified
2025-04-14
First seen
2026-08-07
Aliases
EUVD-2022-51581, GHSA-PQV9-66JX-6Q5V
Products
ASUS:NAS-M25 0 ≤1.0.1.7
Sources
euvd EUVD-2022-51581

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

References