CVE-2016-6557: The ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, is vulnerable to cross-site request forgery
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6557?
CVE-2016-6557 is classified as a high severity vulnerability due to potential unauthorized actions by attackers.
How do I fix CVE-2016-6557?
To fix CVE-2016-6557, update the ASUS RP-AC52 access point firmware to a version later than 1.0.1.1s.
What types of devices are affected by CVE-2016-6557?
CVE-2016-6557 affects the ASUS RP-AC52 access point specifically with firmware version 1.0.1.1s and possibly earlier versions.
What kind of attacks can CVE-2016-6557 enable?
CVE-2016-6557 can enable attackers to perform unauthorized actions with the same permissions as legitimate users.
Is there a workaround for CVE-2016-6557?
There are no specific workarounds for CVE-2016-6557; updating the firmware is the recommended action.