CVE-2020-35219: Critical severity asus dsl-n17u firmware vulnerability
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to AdvancedSystemContent.asp with the uiViewToolsusername=admin&uiViewToolsPassword= and uiViewToolsPasswordConfirm= substrings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35219?
CVE-2020-35219 is a vulnerability where the ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication.
What is the severity of CVE-2020-35219?
The severity of CVE-2020-35219 is critical with a CVSS score of 9.8.
How can an attacker exploit CVE-2020-35219?
An attacker can exploit CVE-2020-35219 by sending a POST request to Advanced_System_Content.asp with specific parameters to change the admin password without authentication.
Which ASUS DSL-N17U modem firmware version is affected?
Firmware version 1.1.0.2 of the ASUS DSL-N17U modem is affected by CVE-2020-35219.
How can I fix CVE-2020-35219?
To fix CVE-2020-35219, ASUS DSL-N17U modem users should update their firmware to a version that is not affected by this vulnerability and apply all available security patches.