A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory/ |
|
History
Tue, 25 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus router |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:asus:router:3.0.0.4_386:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.4_388:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.6_102:*:*:*:*:*:*:* |
|
| Vendors & Products |
Asus
Asus router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published: 2025-11-25T07:30:09.518Z
Updated: 2025-11-26T04:55:21.000Z
Reserved: 2025-09-15T01:36:47.358Z
Link: CVE-2025-59370
Updated: 2025-11-25T14:08:21.411Z
Status : Awaiting Analysis
Published: 2025-11-25T08:15:52.810
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-59370
No data.