CVE-2018-14711: CSRF
Published May 13, 2019
·Updated
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.
Affected Software
2 affected components
ASUS Rt-ac3200 Firmware=3.0.0.4.382.50010
ASUS RT-AC3200
Event History
May 13, 2019
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
Description
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
CVE-2018-14711.
2
What is the severity of CVE-2018-14711?
The severity of CVE-2018-14711 is medium.
3
What does CVE-2018-14711 allow attackers to do?
CVE-2018-14711 allows attackers to cause state-changing actions with specially crafted URLs.
4
Which version of ASUS RT-AC3200 is affected by CVE-2018-14711?
Version 3.0.0.4.382.50010 of ASUS RT-AC3200 is affected by CVE-2018-14711.
5
Is ASUS RT-AC3200 vulnerable to CVE-2018-14711?
No, ASUS RT-AC3200 is not vulnerable to CVE-2018-14711.