header-logo
Suggest Exploit
vendor:
ADSL Routers
by:
SecurityFocus
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: ADSL Routers
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

Information Disclosure in Asus ADSL Routers

It has been reported that remote users may be able to obtain sensitive information from Asus ADSL routers. It is possible to request files from the built-in Web server that contain information such as usernames, passwords and other configuration information.

Mitigation:

Users should ensure that the router is configured to only allow access from trusted hosts.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/8183/info

It has been reported that remote users may be able to obtain sensitive information from Asus ADSL routers. It is possible to request files from the built-in Web server that contain information such as usernames, passwords and other configuration information.

http://<host>/userdata

http://<host>/snmpinit
cqrsecured