CVE-2017-12590: XSS
Published Mar 16, 2018
·Updated
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
Affected Software
2 affected components
ASUS Rt-n14uhp Firmware<3.0.0.4.380.8015
ASUS RT-N14UHP
Event History
Mar 16, 2018
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for ASUS RT-N14UHP devices?
The vulnerability ID for ASUS RT-N14UHP devices is CVE-2017-12590.
2
What is the title of the vulnerability?
The title of the vulnerability is 'ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the flag parameter.'
3
What is the severity of CVE-2017-12590?
The severity of CVE-2017-12590 is medium with a severity value of 6.1.
4
How does the vulnerability impact ASUS RT-N14UHP devices?
The vulnerability allows for reflected cross-site scripting (XSS) attacks via the 'flag' parameter, which could lead to unauthorized access to sensitive information or the execution of malicious code.
5
How can I fix the ASUS RT-N14UHP vulnerability?
To fix the vulnerability, it is recommended to update the firmware of the device to version 3.0.0.4.380.8015 or later, which resolves the reflected XSS vulnerability.