CVE-2017-5892: Infoleak
Published May 10, 2017
·Updated
ASUS RT-AC and RT-N devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.
Affected Software
2 affected components
ASUS Rt-ac1750 Firmware=3.0.0.4.380.7266
ASUS RT-AC1750
Remediation
Patch Available
Event History
May 10, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-5892?
The severity of CVE-2017-5892 is rated as high with a score of 7.5.
2
How do I fix CVE-2017-5892?
To fix CVE-2017-5892, update the firmware of ASUS RT-AC* and RT-N* devices to version 3.0.0.4.380.7378 or later.
3
What devices are affected by CVE-2017-5892?
CVE-2017-5892 affects ASUS RT-AC* and RT-N* devices with firmware versions prior to 3.0.0.4.380.7378.
4
What type of vulnerability is CVE-2017-5892?
CVE-2017-5892 is a JSONP Information Disclosure vulnerability.
5
What can be disclosed due to CVE-2017-5892?
CVE-2017-5892 may allow attackers to gain access to sensitive information, such as a network map.