In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
2018-07-13T20:29:00.817
2024-11-21T02:56:21.063
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | rp-ac52_firmware | ≤ 1.0.1.1s | Yes |
Hardware | asus | rp-ac52 | - | No |
Operating System | asus | ea-n66_firmware | - | Yes |
Hardware | asus | ea-n66 | - | No |
Operating System | asus | rp-n12_firmware | - | Yes |
Hardware | asus | rp-n12 | - | No |
Operating System | asus | rp-n14_firmware | - | Yes |
Hardware | asus | rp-n14 | - | No |
Operating System | asus | rp-n53_firmware | - | Yes |
Hardware | asus | rp-n53 | - | No |
Operating System | asus | rp-ac56_firmware | - | Yes |
Hardware | asus | rp-ac56 | - | No |
Operating System | asus | wmp-n12_firmware | - | Yes |
Hardware | asus | wmp-n12 | - | No |