CVE-2020-15498

MEDIUM

ASUS RT-AC1900P Firmware < 3.0.0.4.385.20253 - Improper Certificate Validation via wget --no-check-certificate Option

Title source: llm
STIX 2.1

Description

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (1)
asus/rt-ac1900p_firmware < 3.0.0.4.385.20253
Published Aug 26, 2020
Tracked Since Feb 18, 2026