Missing CSRF Protection in ASUS RT-AC3200 Router
CVE-2018-14711

6.5MEDIUM

Key Information:

Vendor
Asus
Vendor
CVE Published:
13 May 2019

Summary

The ASUS RT-AC3200 router suffers from a lack of adequate protection against cross-site request forgery (CSRF) in its appGet.cgi component. This vulnerability allows attackers to execute unauthorized state-changing actions by sending specifically crafted URLs to unsuspecting users. Users of this router model must take immediate steps to secure their devices to mitigate the risk of exploitation from this flaw.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.