CVE-2017-15653

Severity
8.8HIGH
EPSS
0.3%
top 46.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateMay 14

Description

Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDasus/asuswrt3.0.0.4.380.7743

🔴Vulnerability Details

2
GHSA
GHSA-qx8p-7xc2-fw37: Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 32022-05-14
CVEList
CVE-2017-15653: Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 32018-01-31
CVE-2017-15653 (HIGH CVSS 8.8) | Improper administrator IP validatio | cvebase.io