CVE-2020-23648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
19/10/2022
Last modified:
09/05/2025

Description

Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-n12e_firmware:2.0.0.39:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-n12e:-:*:*:*:*:*:*:*