SB2017051102 - Two vulnerabilities in Asus RT
Published: May 11, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Cross-site request forgery (CVE-ID: CVE-2017-5891)
The vulnerability allows a remote attacker to perform CSRF attacks.
The vulnerability exists due to improper validation of the HTTP request origin. A remote attacker can create a specially specially crafted web page, trick the authenticated victim into visiting it, perform cross-site request forgery attack and hijack the authentication of unspecified victims.
Successful exploitation of the vulnerability may result in cross-site request forgery conducting.2) Information disclosure (CVE-ID: CVE-2017-5892)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists due to improper access control. A remote attacker can access arbitrary files without login to the router.
Remediation
Install update from vendor's website.