CVE-2017-8878: Infoleak
Published May 10, 2017
·Updated
ASUS RT-AC and RT-N devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPSinfo.xml.
Affected Software
2 affected components
ASUS Rt-ac1750 Firmware=3.0.0.4.380.7266
ASUS RT-AC1750
Event History
May 10, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8878?
CVE-2017-8878 has a medium severity due to the potential for remote authenticated users to discover Wi-Fi passwords.
2
How do I fix CVE-2017-8878?
To fix CVE-2017-8878, upgrade the firmware of your ASUS RT-AC* and RT-N* devices to version 3.0.0.4.380.7378 or later.
3
Which devices are affected by CVE-2017-8878?
CVE-2017-8878 affects ASUS RT-AC and RT-N series devices running firmware earlier than 3.0.0.4.380.7378.
4
What type of attack is CVE-2017-8878 associated with?
CVE-2017-8878 is associated with an information disclosure vulnerability allowing exposure of Wi-Fi passwords.
5
Can I prevent exploitation of CVE-2017-8878?
To prevent exploitation of CVE-2017-8878, ensure your router firmware is regularly updated and use strong authentication methods.