CVE Database
/

CVE-2016-6557

Back to search

CVE-2016-6557

Published: Jul 13, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.

VendorProductVersions

ASUS

RP-AC52 Access Point

affected
1.0.1.1s

Weaknesses (CWE)

References

93596
vdb-entry
x_refsource_BID
VU#763843
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now