Two vulnerabilities in Asus RT



Published: 2017-05-11
Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2017-5891
CVE-2017-5892
CWE-ID CWE-352
CWE-200
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Public exploit code for vulnerability #2 is available.
Vulnerable software
Subscribe
RT-N600
Hardware solutions / Routers for home users

RT-N300
Hardware solutions / Routers for home users

RT-N66W
Hardware solutions / Routers for home users

RT-N66U
Hardware solutions / Routers for home users

RT-N66R
Hardware solutions / Routers for home users

RT-N56U
Hardware solutions / Routers for home users

RT-N16
Hardware solutions / Routers for home users

RT-N12E
Hardware solutions / Routers for home users

RT-N12+
Hardware solutions / Routers for home users

RT-N12
Hardware solutions / Routers for home users

RT-N11P
Hardware solutions / Routers for home users

RT-AC5300
Hardware solutions / Routers for home users

RT-AC3200
Hardware solutions / Routers for home users

RT-AC3100
Hardware solutions / Routers for home users

RT-AC1750
Hardware solutions / Routers for home users

RT-AC1200
Hardware solutions / Routers for home users

RT-AC88U
Hardware solutions / Routers for home users

RT-AC87U
Hardware solutions / Routers for home users

RT-AC87R
Hardware solutions / Routers for home users

RT-AC68R
Hardware solutions / Routers for home users

RT-AC68P
Hardware solutions / Routers for home users

RT-AC68W
Hardware solutions / Routers for home users

RT-AC66W
Hardware solutions / Routers for home users

RT-AC68UF
Hardware solutions / Routers for home users

RT-AC68U
Hardware solutions / Routers for home users

RT-AC66U
Hardware solutions / Routers for home users

RT-AC56U
Hardware solutions / Routers for home users

RT-AC56S
Hardware solutions / Routers for home users

RT-AC56R
Hardware solutions / Routers for home users

RT-AC55U
Hardware solutions / Routers for home users

RT-AC53
Hardware solutions / Routers for home users

RT-AC52U B1
Hardware solutions / Routers for home users

RT-AC51U
Hardware solutions / Routers for home users

Vendor Asus

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Cross-site request forgery

EUVDB-ID: #VU6511

Risk: Medium

CVSSv3.1: 2.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2017-5891

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform CSRF attacks.

The vulnerability exists due to improper validation of the HTTP request origin. A remote attacker can create a specially specially crafted web page, trick the authenticated victim into visiting it, perform cross-site request forgery attack and hijack the authentication of unspecified victims.

Successful exploitation of the vulnerability may result in cross-site request forgery conducting.

Mitigation

Update to version 3.0.0.4.380.7378 or later.

Vulnerable software versions

RT-N600: All versions

RT-N300: All versions

RT-N66W: All versions

RT-N66U: B1

RT-N66R: All versions

RT-N56U: All versions

RT-N16: All versions

RT-N12E: All versions

RT-N12+: All versions

RT-N12: D1

RT-N11P: All versions

RT-AC5300: All versions

RT-AC3200: All versions

RT-AC3100: All versions

RT-AC1750: All versions

RT-AC1200: All versions

RT-AC88U: All versions

RT-AC87U: All versions

RT-AC87R: All versions

RT-AC68R: All versions

RT-AC68P: All versions

RT-AC68W: All versions

RT-AC66W: All versions

RT-AC68UF: All versions

RT-AC68U: All versions

RT-AC66U: All versions

RT-AC56U: All versions

RT-AC56S: All versions

RT-AC56R: All versions

RT-AC55U: All versions

RT-AC53: All versions

RT-AC52U B1: All versions

RT-AC51U: All versions

External links

http://wwws.nightwatchcybersecurity.com/2017/05/09/multiple-vulnerabilities-in-asus-routers/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) Information disclosure

EUVDB-ID: #VU6512

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2017-5892

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to improper access control. A remote attacker can access arbitrary files without login to the router.

Successful exploitation of the vulnerability may result in JSONP information disclosure.

Mitigation

Install update from vendor's website.

Vulnerable software versions

RT-N600: All versions

RT-N300: All versions

RT-N66W: All versions

RT-N66U: B1

RT-N66R: All versions

RT-N56U: All versions

RT-N16: All versions

RT-N12E: All versions

RT-N12+: All versions

RT-N12: D1

RT-N11P: All versions

RT-AC5300: All versions

RT-AC3200: All versions

RT-AC3100: All versions

RT-AC1750: All versions

RT-AC1200: All versions

RT-AC88U: All versions

RT-AC87U: All versions

RT-AC87R: All versions

RT-AC68R: All versions

RT-AC68P: All versions

RT-AC68W: All versions

RT-AC66W: All versions

RT-AC68UF: All versions

RT-AC68U: All versions

RT-AC66U: All versions

RT-AC56U: All versions

RT-AC56S: All versions

RT-AC56R: All versions

RT-AC55U: All versions

RT-AC53: All versions

RT-AC52U B1: All versions

RT-AC51U: All versions

External links

http://wwws.nightwatchcybersecurity.com/2017/05/09/multiple-vulnerabilities-in-asus-routers/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###