CVE-2025-15101

8.8

ASUS · Router models

An OS command injection vulnerability exists in the web management interface of certain ASUS routers, allowing authenticated administrators to execute arbitrary system commands via a crafted parameter.

Executive summary

An OS command injection flaw in ASUS router firmware allows authenticated administrators to execute arbitrary system commands, posing a severe risk to network infrastructure.

Vulnerability

This vulnerability is an OS Command Injection (CWE-78) flaw within the web management interface. It requires the attacker to hold administrative privileges (authenticated) to successfully trigger the execution of arbitrary system commands through a malicious parameter.

Business impact

The ability to execute arbitrary system commands on network infrastructure represents a critical security failure. A successful exploit could lead to full device compromise, unauthorized network access, and the potential for lateral movement into the internal network, justifying the high CVSS score of 8.8.

Remediation

Immediate Action: Update the affected ASUS router firmware to the latest version provided by the vendor to remediate the command injection vector.

Proactive Monitoring: Review device management logs for irregular administrative activity and monitor network traffic for unexpected outbound connections originating from the router management interface.

Compensating Controls: Restrict access to the web management interface to trusted internal IP addresses only, and ensure that administrative credentials are complex and unique to prevent unauthorized access.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of OS command injection vulnerabilities in networking hardware, administrators must prioritize applying the latest firmware updates. Immediate action is required to ensure that router management interfaces are not leveraged to gain unauthorized control over the network environment.

More ASUS CVEs

Sources

Originally found and disclosed by Per Idenfeldt Okuyama at CYLOQ, per the CVE Program record.