Security Advisory

CVE-2017-15653

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-01-31 20:00:00
Last updated 2024-08-05 19:57:27
Assigner mitre
State PUBLISHED

Description

Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.