Cross-Site Scripting Vulnerability in ASUS Routers
CVE-2017-6547

6.1MEDIUM

Key Information:

Vendor
Asus
Vendor
CVE Published:
9 March 2017

Summary

ASUS routers with outdated firmware are susceptible to a cross-site scripting vulnerability which allows remote attackers to inject malicious JavaScript code. By sending requests with filenames longer than 50 characters, attackers can exploit this vulnerability to take control over user sessions or manipulate the content visible to users. This affects numerous models, including RT-N56U and RT-AC87U, urging users to update their firmware to mitigate potential risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.