CVE-2014-7270

Severity
6.8MEDIUM
EPSS
0.1%
top 68.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allows remote attackers to hijack the authentication of arbitrary users.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDasus/rt-n56u_firmware3.0.0.4.376.3715
NVDasus/rt-n66u_firmware3.0.0.4.376.3715
NVDasus/rt-ac56s_firmware3.0.0.4.376.3715
NVDasus/rt-ac68u_firmware3.0.0.4.376.3715
NVDasus/rt-ac87u_firmware3.0.0.4.378.3754

🔴Vulnerability Details

2
GHSA
GHSA-hhfv-v628-qxv3: Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 32022-05-17
CVEList
CVE-2014-7270: Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 32015-02-01
CVE-2014-7270 (MEDIUM CVSS 6.8) | Cross-site request forgery (CSRF) v | cvebase.io