Missing CSRF Protection in ASUS RT-AC3200 Router
CVE-2018-14711
6.5MEDIUM
Summary
The ASUS RT-AC3200 router suffers from a lack of adequate protection against cross-site request forgery (CSRF) in its appGet.cgi component. This vulnerability allows attackers to execute unauthorized state-changing actions by sending specifically crafted URLs to unsuspecting users. Users of this router model must take immediate steps to secure their devices to mitigate the risk of exploitation from this flaw.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved