CVE-2017-14698: Critical severity asus dsl-ac51 firmware vulnerability
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote attackers to change passwords of arbitrary users via the httppasswd parameter to modlogin.asp.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this ASUS router vulnerability?
The vulnerability ID for this ASUS router vulnerability is CVE-2017-14698.
What is the severity of CVE-2017-14698?
The severity of CVE-2017-14698 is critical with a score of 9.8.
Which ASUS router models are affected by CVE-2017-14698?
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers are affected by CVE-2017-14698.
How can remote attackers exploit CVE-2017-14698?
Remote attackers can exploit CVE-2017-14698 by changing passwords of arbitrary users using the http_passwd parameter to mod_login.
Is there a fix available for CVE-2017-14698?
Yes, you can find the fix for CVE-2017-14698 on ASUS' official website.