An issue exists on ASUS RT-AC1900P routers prior to 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
asus rt-ac1900p_firmware |