PT-2024-4602 · Asus · Asus Rt-N12+ B1

Published

2024-03-08

·

Updated

2024-12-28

·

CVE-2024-28326

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ASUS RT-N12+ B1 versions (affected versions not specified) ASUS RT-N12 D1 versions (affected versions not specified)
Description: The issue is related to insufficient access control in the UART interface of the firmware of ASUS routers, allowing local attackers to gain unauthorized access to the root terminal. This can be exploited through the UART interface, potentially giving attackers root access to the device.
Recommendations: For ASUS RT-N12+ B1, restrict access to the UART interface until a patch is available. For ASUS RT-N12 D1, restrict access to the UART interface until a patch is available. As a temporary workaround, consider disabling the UART interface on both models to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2024-05110
CVE-2024-28326

Affected Products

Asus Rt-N12+ B1