{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-15101", "assignerOrgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1", "state": "PUBLISHED", "assignerShortName": "ASUS", "dateReserved": "2025-12-26T02:08:21.482Z", "datePublished": "2026-03-26T02:01:26.642Z", "dateUpdated": "2026-05-13T01:44:37.638Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1", "shortName": "ASUS", "dateUpdated": "2026-05-13T01:44:37.638Z" }, "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-78", "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')", "type": "CWE" } ] } ], "affected": [ { "vendor": "ASUS", "product": "Router", "versions": [ { "status": "affected", "version": "3.0.0.6_102" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter.\nRefer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "