Access Control Vulnerability in Asus RT-N12E Router
CVE-2020-23648

7.5HIGH

Key Information:

Vendor
Asus
Vendor
CVE Published:
19 October 2022

Summary

The Asus RT-N12E version 2.0.0.39 is susceptible to an access control flaw that allows unauthorized users to change the administrator password without any form of authentication. This vulnerability can be exploited through specific endpoints, namely system.asp and start_apply.htm, potentially compromising the entire network security and allowing further malicious activities.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.