qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request.
2013-10-05T10:55:03.493
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.1 (MEDIUM)
AV:A/AC:L/Au:N/C:C/I:N/A:N
6.5
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | rt-n10e_firmware | ≤ 2.0.0.24 | Yes |
Operating System | asus | rt-n10e_firmware | 2.0.0.7 | Yes |
Operating System | asus | rt-n10e_firmware | 2.0.0.10 | Yes |
Operating System | asus | rt-n10e_firmware | 2.0.0.16 | Yes |
Operating System | asus | rt-n10e_firmware | 2.0.0.19 | Yes |
Operating System | asus | rt-n10e_firmware | 2.0.0.20 | Yes |
Hardware | asus | rt-n10e | - | Yes |