CVE-2020-23648: High severity asus rt-n12e firmware vulnerability
Published Oct 19, 2022
·Updated
Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / startapply.htm, an attacker can change the administrator password without any authentication.
Affected Software
4 affected components
ASUS Rt-n12e Firmware=2.0.0.39
ASUS RT-N12E
All of the following
ASUS Rt-n12e Firmware=2.0.0.39
ASUS RT-N12E
Event History
Oct 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-23648.
2
What is the severity of CVE-2020-23648?
The severity of CVE-2020-23648 is high, with a severity value of 7.5.
3
What is the affected software?
The affected software is Asus RT-N12E firmware version 2.0.0.39.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by accessing the system.asp/start_apply.htm pages and changing the administrator password without authentication.
5
How can I fix CVE-2020-23648?
To fix CVE-2020-23648, update your Asus RT-N12E firmware to a version that is not affected by this vulnerability.