PT-2024-4603 · Asus · Asus Rt-N12+ B1

Published

2024-03-08

·

Updated

2024-11-04

·

CVE-2024-28327

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ASUS RT-N12+ B1 router version not specified
Description: The issue is related to inadequate protection of registration data in the router's firmware, allowing local attackers to obtain unauthorized access and modify router settings. This is because the router stores user passwords in plaintext.
Recommendations: For the ASUS RT-N12+ B1 router, consider changing the administrator password and any other passwords stored on the device to minimize the risk of exploitation. As a temporary workaround, restrict local access to the router until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-05111
CVE-2024-28327

Affected Products

Asus Rt-N12+ B1