← back
CVE-2024-28326mediumCWE-1263

CVE-2024-28326

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
In short

ASUS RT-N12+ B1 and RT-N12 D1 routers have a security flaw that allows someone with physical access to the UART interface to gain complete root control of the device. This matters because it exposes the router to full compromise if an attacker can physically access it.

Technical detail

Incorrect access control on the UART interface in ASUS RT-N12+ B1 and RT-N12 D1 routers permits local attackers with physical access to the serial port to obtain root terminal privileges. The vulnerability stems from insufficient authentication mechanisms protecting the UART debug interface, enabling arbitrary command execution with elevated privileges.

Summary generated and translated by AI from the official description.
Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a