CVE-2022-25595: ASUS RT-AC86U - Improper Input Validation
Published Apr 7, 2022
·Updated
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
Affected Software
2 affected components
ASUS Rt-ac86u Firmware=3.0.0.4.386.45956
ASUS RT-AC86U
Remediation
Information
Update ASUS RT-AC86U firmware version to 3.0.0.4_386_46092
Event History
Apr 7, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-25595?
CVE-2022-25595 is a vulnerability in ASUS RT-AC86U firmware that allows an unauthenticated LAN attacker to cause a denial of service by sending a particular request.
2
How severe is CVE-2022-25595?
CVE-2022-25595 has a severity rating of 6.5 (medium).
3
Which software versions are affected by CVE-2022-25595?
ASUS RT-AC86U firmware version 3.0.0.4.386.45956 is affected by CVE-2022-25595.
4
How can an unauthenticated LAN attacker exploit CVE-2022-25595?
An unauthenticated LAN attacker can exploit CVE-2022-25595 by sending a specific request to the vulnerable ASUS RT-AC86U router.
5
Is ASUS RT-AC86U the only affected device?
Yes, ASUS RT-AC86U is the only affected device by CVE-2022-25595.