2 results (0.005 seconds)

CVSS: 4.8EPSS: 0%CPEs: 2EXPL: 0

16 Feb 2025 — A vulnerability was found in Asus RT-N12E 2.0.0.19. It has been classified as problematic. Affected is an unknown function of the file sysinfo.asp. The manipulation of the argument SSID leads to cross site scripting. It is possible to launch the attack remotely. • https://vuldb.com/?ctiid.295962 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 1

19 Oct 2022 — Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication. Asus RT-N12E versión 2.0.0.39, está afectado por una vulnerabilidad de control de acceso incorrecto. Mediante el archivo system.asp / start_apply.htm, un atacante puede cambiar la contraseña del administrador sin ninguna autenticación • https://gist.github.com/ninj4c0d3r/574d2753d469e4ba51dfe555d9c2d4fb • CWE-306: Missing Authentication for Critical Function •