ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
BID:49308
Info
ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
| Bugtraq ID: | 49308 |
| Class: | Design Error |
| CVE: |
CVE-2011-4497 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2011 12:00AM |
| Updated: | Nov 22 2011 06:25PM |
| Credit: | Plucky |
| Vulnerable: |
Asus RT-N56U 1.0.1.4 |
| Not Vulnerable: |
Asus RT-N56U 1.0.1.4o |
Discussion
ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
ASUS RT-N56U wireless router is prone to an information-disclosure vulnerability that exposes sensitive information.
Successful exploits will allow unauthenticated attackers to obtain sensitive information of the device such as administrative password, which may aid in further attacks.
ASUS RT-N56U firmware version 1.0.1.4 is vulnerable.
ASUS RT-N56U wireless router is prone to an information-disclosure vulnerability that exposes sensitive information.
Successful exploits will allow unauthenticated attackers to obtain sensitive information of the device such as administrative password, which may aid in further attacks.
ASUS RT-N56U firmware version 1.0.1.4 is vulnerable.
Exploit / POC
ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ASUS RT-N56U Wireless Router 'QIS_wizard.htm' Password Information Disclosure Vulnerability
References:
References:
- ASUS RT-N56U remote password disclosure vulnerability (CERT)
- RT-N56U Wireless Router (ASUS)
- Vendor Homepage (ASUS)