CVE-2017-6549: High severity ASUS Rt-ac53 Firmware vulnerability

Published Mar 9, 2017
·
Updated

Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.652 allows remote attackers to steal any active admin session by sending cgilogout and asusrouter-Windows-IFTTT-1.0 in certain HTTP headers.

Affected Software

4 affected components
ASUS Rt-ac53 Firmware=3.0.0.4.380.6038
ASUS RT-AC53
All of the following
ASUS Rt-ac53 Firmware=3.0.0.4.380.6038
ASUS RT-AC53

Event History

Mar 9, 2017
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
Description
Data Sourced
via NVD·09:59 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-6549?

CVE-2017-6549 has been classified as a high severity vulnerability due to its potential for session hijacking.

2

How do I fix CVE-2017-6549?

To fix CVE-2017-6549, you should update the router firmware to version 3.0.0.4.380.6038 or later.

3

Which devices are affected by CVE-2017-6549?

CVE-2017-6549 affects various ASUS router models including RT-N56U, RT-N66U, RT-AC66U, and others with specific firmware versions.

4

What type of vulnerability is CVE-2017-6549?

CVE-2017-6549 is a session hijacking vulnerability that allows attackers to take control of user sessions.

5

Is CVE-2017-6549 still a concern if my router firmware is updated?

No, if your router firmware is updated to the recommended version, CVE-2017-6549 should no longer be a concern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203