Cross-Site Scripting Vulnerability in ASUS Routers
CVE-2017-6547
6.1MEDIUM
What is CVE-2017-6547?
ASUS routers with outdated firmware are susceptible to a cross-site scripting vulnerability which allows remote attackers to inject malicious JavaScript code. By sending requests with filenames longer than 50 characters, attackers can exploit this vulnerability to take control over user sessions or manipulate the content visible to users. This affects numerous models, including RT-N56U and RT-AC87U, urging users to update their firmware to mitigate potential risks.