Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allows remote attackers to hijack the authentication of arbitrary users.
2015-02-01T15:59:03.323
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | rt-n66u_firmware | ≤ 3.0.0.4.376.3715 | Yes |
Hardware | asus | rt-n66u | - | Yes |
Operating System | asus | rt-n56u_firmware | ≤ 3.0.0.4.376.3715 | Yes |
Hardware | asus | rt-n56u | - | Yes |
Operating System | asus | rt-ac87u_firmware | ≤ 3.0.0.4.378.3754 | Yes |
Hardware | asus | rt-ac87u | - | Yes |
Operating System | asus | rt-ac68u_firmware | ≤ 3.0.0.4.376.3715 | Yes |
Hardware | asus | rt-ac68u | - | Yes |
Operating System | asus | rt-ac56s_firmware | ≤ 3.0.0.4.376.3715 | Yes |
Hardware | asus | rt-ac56s | - | Yes |