Summary
This host is running ASUS RT-N10E Wireless Router and is prone to information disclosure vulnerability.
Impact
Successful exploitation will allow remote attacker to disclose certain sensitive information.
Impact Level: Application
Solution
Upgrade to ASUS Wireless-N150 Router RT-N10E firmware 2.0.0.25 or later, For updates refer to http://www.asus.com/Networking/RTN10E/#support_Download
Insight
The flaw is due to the device not properly restricting access to the '/qis/QIS_finish.htm' page.
Affected
ASUS Wireless-N150 Router RT-N10E firmware versions 2.0.0.24 and earlier.
Detection
Send direct HTTP GET request and check it is possible to read the password and other informations or not.
References
Severity
Classification
-
CVE CVE-2013-3610 -
CVSS Base Score: 6.1
AV:A/AC:L/Au:N/C:C/I:N/A:N
Related Vulnerabilities
- AjaXplorer Remote Command Injection and Local File Disclosure Vulnerabilities
- Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
- Apache Struts2 'XWork' Information Disclosure Vulnerability
- 7Media Web Solutions EduTrac Directory Traversal Vulnerability
- 1024 CMS 1.1.0 Beta 'force_download.php' Local File Include Vulnerability