CVE-2018-17023: CSRF
Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.38432738 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to startapply.htm.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17023?
CVE-2018-17023 is a Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738.
How does CVE-2018-17023 affect ASUS GT-AC5300 routers?
CVE-2018-17023 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password.
How severe is CVE-2018-17023?
CVE-2018-17023 has a severity score of 8.8 (high).
How can I fix CVE-2018-17023 on my ASUS GT-AC5300 router?
To fix CVE-2018-17023, update your router's firmware to a version higher than 3.0.0.4.384_32738.
Where can I find more information about CVE-2018-17023?
You can find more information about CVE-2018-17023 at the following reference: https://github.com/PAGalaxyLab/VulInfo/blob/master/ASUS/csrf_bypass_referer/ASUS%20GT-AC5300%20csrf%20bypass%20referer.MD