Release date:
Updated on:
Affected Systems:
Asus RT-N56U 1.0.1.4
Unaffected system:
Asus RT-N56U 1.0.1.4o.
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49308
ASUS RT-N56U is a modern style concurrent dual broadband wireless N Gb router.
The ASUS rt-n56uhas an information leakage vulnerability in the implementation of the qis_wizard.htm password. Remote unauthenticated attackers can exploit this vulnerability to obtain sensitive information of affected devices, such as the administrator password.
The source of this leakage is that there is no limit on the render Display Device Configuration (qis_wizard.htm? Flag = detect), which can be exploited to leak sensitive information.
<* Source: Plucky
Link: http://www.kb.cert.org/vuls/id/200814
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Asus
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.asus.com.tw