CVE-2015-2676: CSRF
Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to startapply.htm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2676?
CVE-2015-2676 has been classified as a moderate severity vulnerability due to its potential to allow unauthorized access to administrative functions.
How do I fix CVE-2015-2676?
To fix CVE-2015-2676, users should upgrade their ASUS RT-G32 router firmware to a version that is not affected by this vulnerability.
What systems are affected by CVE-2015-2676?
CVE-2015-2676 affects ASUS RT-G32 routers running firmware versions 2.0.2.6 and 2.0.3.2.
What type of attack is CVE-2015-2676 associated with?
CVE-2015-2676 is associated with a Cross-Site Request Forgery (CSRF) attack that can hijack an administrator’s authentication.
What can attackers do using CVE-2015-2676?
Using CVE-2015-2676, attackers can change the administrator password on ASUS RT-G32 routers by sending a crafted request.