PT-2015-5828 · Asus · Asus Rt-G32

Mustlive

·

Publicado

2015-03-23

·

Atualizado

2016-12-03

·

CVE-2015-2676

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ASUS RT-G32 routers versions 2.0.2.6 through 2.0.3.2
Description A cross-site request forgery issue allows remote attackers to hijack administrator authentication for requests that change the administrator password via a request to "start apply.htm".
Recommendations For version 2.0.2.6, update the firmware to a version that is not affected by this issue. For version 2.0.3.2, update the firmware to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the "start apply.htm" endpoint to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2676

Produtos afetados

Asus Rt-G32