ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-5793-4f9d3-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-04-07 12:15
Updated : 2022-04-14 13:27
NVD link : CVE-2022-25596
Mitre link : CVE-2022-25596
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
asus
- rt-ac86u_firmware
- rt-ac86u