First published: Mon Jan 04 2021(Updated: )
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Dsl-n17u Firmware | =1.1.0.2 | |
ASUS DSL-N17U |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35219 is a vulnerability where the ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication.
The severity of CVE-2020-35219 is critical with a CVSS score of 9.8.
An attacker can exploit CVE-2020-35219 by sending a POST request to Advanced_System_Content.asp with specific parameters to change the admin password without authentication.
Firmware version 1.1.0.2 of the ASUS DSL-N17U modem is affected by CVE-2020-35219.
To fix CVE-2020-35219, ASUS DSL-N17U modem users should update their firmware to a version that is not affected by this vulnerability and apply all available security patches.