Critical severity9.8NVD Advisory· Published Dec 1, 2022· Updated Jun 17, 2026
CVE-2022-4221
CVE-2022-4221
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- onekey.com/blog/security-advisory-asus-m25-nas-vulnerability/nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.