CVE Published: 13/07/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: certcc |
Vendor: ASUS |
Product: RP-AC52 Access Point Status : PUBLISHED
CVE-2016-6557 Description
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.