CVE-2025-15101
8.8ASUS · Router models
An OS command injection vulnerability exists in the web management interface of certain ASUS routers, allowing authenticated administrators to execute arbitrary system commands via a crafted parameter.
Executive summary
An OS command injection flaw in ASUS router firmware allows authenticated administrators to execute arbitrary system commands, posing a severe risk to network infrastructure.
Vulnerability
This vulnerability is an OS Command Injection (CWE-78) flaw within the web management interface. It requires the attacker to hold administrative privileges (authenticated) to successfully trigger the execution of arbitrary system commands through a malicious parameter.
Business impact
The ability to execute arbitrary system commands on network infrastructure represents a critical security failure. A successful exploit could lead to full device compromise, unauthorized network access, and the potential for lateral movement into the internal network, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Update the affected ASUS router firmware to the latest version provided by the vendor to remediate the command injection vector.
Proactive Monitoring: Review device management logs for irregular administrative activity and monitor network traffic for unexpected outbound connections originating from the router management interface.
Compensating Controls: Restrict access to the web management interface to trusted internal IP addresses only, and ensure that administrative credentials are complex and unique to prevent unauthorized access.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of OS command injection vulnerabilities in networking hardware, administrators must prioritize applying the latest firmware updates. Immediate action is required to ensure that router management interfaces are not leveraged to gain unauthorized control over the network environment.
More ASUS CVEs
Sources
Originally found and disclosed by Per Idenfeldt Okuyama at CYLOQ, per the CVE Program record.