VYPR
High severity7.3NVD Advisory· Published Apr 22, 2022· Updated Jun 17, 2026

CVE-2022-26672

CVE-2022-26672

Description

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the attacker to access, modify or delete this user account information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Asus/WebStorage3 versions
    cpe:2.3:a:asus:webstorage:*:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:asus:webstorage:*:*:*:*:*:android:*:*range: <3.10.2
    • (no CPE)
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.