MEDIUM · 6.3

CVE-2014-2719

Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator ...

Vulnerability Description

Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code.

CVSS Score

6.3

MEDIUM

AV:N/AC:M/Au:S/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AsusRt-Ac66U Firmware3.0.0.4.140
AsusRt-Ac68U Firmware3.0.0.4.374.4755
AsusRt-N10E Firmware2.0.0.7
AsusRt-N14U Firmware3.0.0.4.322
AsusRt-N16 Firmware1.0.1.9
AsusRt-N56U Firmware1.0.1.4
AsusRt-N65U Firmware3.0.0.3.134
AsusRt-N66U Firmware3.0.0.4.272
AsusRt-Ac68U-
T-MobileTm-Ac19003.0.0.4.376_3169

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2719?

CVE-2014-2719 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator ...

How severe is CVE-2014-2719?

CVE-2014-2719 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2719?

Check the references section above for vendor advisories and patch information. Affected products include: Asus Rt-Ac66U Firmware, Asus Rt-Ac68U Firmware, Asus Rt-N10E Firmware, Asus Rt-N14U Firmware, Asus Rt-N16 Firmware.