Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
BID:65733
Info
Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 65733 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Mar 04 2014 01:23AM |
| Credit: | Harry Sintonen of nSense Oy |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
Multiple ASUS Routers are prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker could leverage these issues to gain unauthorized access to the affected device, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected device.
Multiple ASUS Routers are prone to a cross-site scripting vulnerability and an authentication-bypass vulnerability.
An attacker could leverage these issues to gain unauthorized access to the affected device, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected device.
Exploit / POC
Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple ASUS Routers Cross Site Scripting and Authentication Bypass Vulnerabilities
References:
References:
- ASUS Homepage (ASUS)