CVE-2025-1354

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Feb 16, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-1354 is a recently disclosed vulnerability affecting the Asus RT-N12E router running firmware version 2.0.0.19. This issue is considered problematic as it allows for cross-site scripting (XSS) attacks. By manipulating the SSID argument in the sysinfo.asp file, an attacker can inject malicious scripts into a victim's browser. Such attacks can lead to information theft, session hijacking, or even full system takeover. The vulnerability is publicly known, and there is a risk of widespread exploitation, as the vendor, Asus, has not yet responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share