CVE-2016-6557 describes a Cross-Site Request Forgery (CSRF) vulnerability in ASUS RP-AC52 access points with firmware version 1.0.1.1s and earlier. This high-severity vulnerability (CVSS 8.8) allows an unauthenticated attacker to perform actions with the same permissions as a victim user if the victim has an active session and is tricked into triggering a malicious request. While the potential impact includes high confidentiality, integrity, and availability compromise, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.1.1sCPE matchmatch criteria | cpe:2.3:o:asus:rp-ac52_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:asus:ea-n66_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:asus:rp-n12_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:asus:rp-n14_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:asus:rp-n53_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.