CVE-2025-1354: Asus RT-N12E sysinfo.asp cross site scripting
A cross-site scripting (XSS) vulnerability in the RT-N10E/ RT-N12E 2.0.0.x firmware . This vulnerability caused by improper input validation and can be triggered via the manipulation of the SSID argument in the sysinfo.asp file, leading to disclosure of sensitive information. Note: All versions of RT-N10E and RT-N12E are unsupported (End-of-Life, EOL). Consumers can mitigate this vulnerability by disabling the remote access features from WAN
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1354?
CVE-2025-1354 is classified as problematic due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2025-1354?
To fix CVE-2025-1354, it is recommended to update the Asus RT-N12E firmware to the latest version provided by Asus.
What type of vulnerability is CVE-2025-1354?
CVE-2025-1354 is a cross-site scripting (XSS) vulnerability found in the sysinfo.asp file.
Can CVE-2025-1354 be exploited remotely?
Yes, CVE-2025-1354 can be exploited remotely, allowing attackers to manipulate the SSID argument.
Which devices are affected by CVE-2025-1354?
CVE-2025-1354 specifically affects the Asus RT-N12E router.