CVE-2017-5891: CSRF
Published May 10, 2017
·Updated
ASUS RT-AC and RT-N devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.
Affected Software
2 affected components
ASUS Rt-ac1750 Firmware=3.0.0.4.380.7266
ASUS RT-AC1750
Remediation
Patch Available
Event History
May 10, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-5891?
CVE-2017-5891 is classified as a medium severity vulnerability due to its potential for unauthorized access to router configuration.
2
How do I fix CVE-2017-5891?
To fix CVE-2017-5891, upgrade your ASUS RT-AC* and RT-N* devices firmware to version 3.0.0.4.380.7378 or later.
3
What types of attacks can CVE-2017-5891 facilitate?
CVE-2017-5891 allows attackers to exploit Cross-Site Request Forgery (CSRF) vulnerabilities to change router settings without user consent.
4
Which ASUS devices are affected by CVE-2017-5891?
CVE-2017-5891 affects ASUS RT-AC and RT-N series devices that are running firmware versions prior to 3.0.0.4.380.7378.
5
What can happen if I don’t address CVE-2017-5891?
If CVE-2017-5891 is not addressed, it may lead to unauthorized configuration changes or access to the network.