Summary
Detail | |||
---|---|---|---|
Vendor | Asus | First view | 2017-08-18 |
Product | Dsl-n10s Firmware | Last view | 2017-08-18 |
Version | v2.1.16_apac | Type | Os |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:o:asus:dsl-n10s_firmware |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2017-08-18 | CVE-2017-12593 | ASUS DSL-N10S V2.1.16_APAC devices allow CSRF. |
8.8 | 2017-08-18 | CVE-2017-12592 | ASUS DSL-N10S V2.1.16_APAC devices have a privilege escalation vulnerability. A normal user can escalate its privilege and perform administrative actions. There is no mapping of users with their privileges. |
5.4 | 2017-08-18 | CVE-2017-12591 | ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |