An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.
The vulnerability results from flawed implementation of authentication mechanisms (CWE-288) or complete absence of required authentication for critical functions (CWE-306). A network attacker can bypass login procedures without needing any credentials, user interaction, or fulfillment of special conditions. The attack can be conducted remotely over the network, which significantly increases the risk of exploitation.
An attacker can gain unauthorized access to the router's management system, potentially allowing full control of the device, modification of network configuration, and enabling further attacks on devices in the local network.
Apply patches available from the manufacturer according to the references — detailed information about firmware updates can be found in the ASUS Security Advisory message in the 'Security Update for DSL Series Router' section at https://www.asus.com/security-advisory
ASUS DSL-AC51, ASUS DSL-AC51 Firmware, ASUS DSL-N16, ASUS DSL-N16 Firmware, ASUS DSL-AC750 — specific firmware versions indicated in the manufacturer's references (ASUS Security Advisory, 'Security Update for DSL Series Router' section)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAsus Dsl Ac51
HWAsusall versionsAsus Dsl Ac51 Firmware
OSAsus< 1.1.2.3_1010Asus Dsl Ac750
HWAsusall versionsAsus Dsl Ac750 Firmware
OSAsus< 1.1.2.3_1010Asus Dsl N16
HWAsusall versionsAsus Dsl N16 Firmware
OSAsus< 1.1.2.3_1010
Related vulnerabilities
ASUS DSL — zdalna zmiana hasła dowolnego użytkownika (Auth Bypass)
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC5...
ASUS Live Update — kompromitacja łańcucha dostaw (supply chain compromise)
Authentication bypass w urządzeniach ASUS GT-AC2900 i Lyra Mini
ASUS Armoury Crate — zapis i odczyt dowolnych plików przez sieć bez uwierzytelnienia