4.3
CVSSv2

CVE-2017-6547

Published: 09/03/2017 Updated: 16/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware prior to 3.0.0.4.380.7378; RT-AC68W routers with firmware prior to 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware prior to 3.0.0.4.380.9488 allows remote malicious users to inject arbitrary JavaScript by requesting filenames longer than 50 characters.

Vulnerable Product Search on Vulmon Subscribe to Product

asus rt-ac53_firmware 3.0.0.4.380.6038

Exploits

Cross-Site Scripting (XSS) Component: httpd CVE: CVE-2017-6547 Vulnerability: httpd checks in the function handle_request if the requested file name is longer than 50 chars It then responds with a redirection which allows an attacker to inject arbitrary JavaScript code into the router’s web interface context if(strlen(file) > 50 &a ...
This NSE script for Nmap exploits a cross site scripting vulnerability in ASUS WRT ...