ID

VAR-201602-0414


TITLE

ASUS RT-N56U HTML Injection Vulnerability

Trust: 1.5

sources: CNVD: CNVD-2016-01255 // BID: 82667 // CNNVD: CNNVD-201602-377

DESCRIPTION

The ASUSRT-N56U has an HTML injection vulnerability that allows remote attackers to exploit malicious exploits to inject malicious scripts or HTML code to capture sensitive information or hijack user sessions when malicious data is viewed. ASUS RT-N56U is a wireless router product from ASUS. An HTML injection vulnerability exists in ASUS RT-N56U. When a user browses an affected website, their browser executes any HTML or script code provided by the attacker. This could lead to attackers stealing cookie-based authentication or controlling how the site is presented to users. Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible

Trust: 1.35

sources: CNVD: CNVD-2016-01255 // CNNVD: CNNVD-201602-377 // BID: 82667

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-01255

AFFECTED PRODUCTS

vendor:asusmodel:rt-n56uscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-01255

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-01255
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-01255
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-01255

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201602-377

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201602-377

EXTERNAL IDS

db:BIDid:82667

Trust: 1.5

db:CNVDid:CNVD-2016-01255

Trust: 0.6

db:CNNVDid:CNNVD-201602-377

Trust: 0.6

sources: CNVD: CNVD-2016-01255 // BID: 82667 // CNNVD: CNNVD-201602-377

REFERENCES

url:http://www.securityfocus.com/bid/82667

Trust: 1.2

url:http://www.asus.com/networking/rtn56u/

Trust: 0.3

url:http://seclists.org/bugtraq/2016/feb/12

Trust: 0.3

sources: CNVD: CNVD-2016-01255 // BID: 82667 // CNNVD: CNNVD-201602-377

CREDITS

GraphX

Trust: 0.9

sources: BID: 82667 // CNNVD: CNNVD-201602-377

SOURCES

db:CNVDid:CNVD-2016-01255
db:BIDid:82667
db:CNNVDid:CNNVD-201602-377

LAST UPDATE DATE

2022-05-17T01:51:03.733000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-01255date:2016-02-24T00:00:00
db:BIDid:82667date:2016-07-06T12:16:00
db:CNNVDid:CNNVD-201602-377date:2016-02-19T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-01255date:2016-02-24T00:00:00
db:BIDid:82667date:2016-02-02T00:00:00
db:CNNVDid:CNNVD-201602-377date:2016-02-19T00:00:00