CVE-2025-1354
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/02/2025
Last modified:
13/03/2025
Description
A cross-site scripting (XSS) vulnerability in the RT-N10E/ RT-N12E 2.0.0.x firmware . This vulnerability caused by improper input validation and can be triggered via the manipulation of the SSID argument in the sysinfo.asp file, leading to disclosure of sensitive information. Note: All versions of RT-N10E and RT-N12E are unsupported (End-of-Life, EOL). Consumers can mitigate this vulnerability by disabling the remote access features from WAN
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
2.40
Severity 3.x
LOW
Base Score 2.0
3.30
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://vuldb.com/?ctiid_295962=
- https://vuldb.com/?id_295962=
- https://vuldb.com/?submit_496013=
- https://www.asus.com/supportonly/rt-n10e/helpdesk_bios/
- https://www.asus.com/supportonly/rt-n12e/helpdesk_bios/
- https://vuldb.com/?ctiid_295962=
- https://vuldb.com/?id_295962=
- https://vuldb.com/?submit_496013=
- https://www.asus.com/