8.8
CVE-2022-25596
- EPSS 0.57%
- Veröffentlicht 07.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:24
- Erkennungen
ASUS RT-AC86U - Heap-based buffer overflow
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asus ≫ Rt-ac86u Firmware Version 3.0.0.4.386.45956
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.57% | 0.439 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
| Cert TW | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.twcert.org.tw/tw/cp-132-5793-4f9d3-1.html