Multiple ASUS RT Routers CVE-2014-7270 Unspecified Cross Site Request Forgery Vulnerability
BID:72392
Info
Multiple ASUS RT Routers CVE-2014-7270 Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 72392 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7270 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2015 12:00AM |
| Updated: | Jan 28 2015 12:00AM |
| Credit: | Masashi Sakai |
| Vulnerable: |
Asus Rt-N66u 3.0.0.4.376.3715 Asus RT-N56U 3.0.0.4.376.3715 Asus RT-AC87U 3.0.0.4.378.3754 Asus RT-AC68U 3.0.0.4.376.3715 Asus RT-AC56S 3.0.0.4.376.3715 |
| Not Vulnerable: | |
Discussion
Multiple ASUS RT Routers CVE-2014-7270 Unspecified Cross Site Request Forgery Vulnerability
Multiple ASUS RT Routers are prone to an unspecified cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected device. Other attacks are also possible.
Multiple ASUS RT Routers are prone to an unspecified cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected device. Other attacks are also possible.
Exploit / POC
Multiple ASUS RT Routers CVE-2014-7270 Unspecified Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
Multiple ASUS RT Routers CVE-2014-7270 Unspecified Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.