CVE-2017-5891 is a Cross-Site Request Forgery (CSRF) vulnerability affecting various ASUS RT-AC* and RT-N* router models with firmware versions prior to 3.0.0.4.380.7378. This flaw, rated 8.8 HIGH on the CVSS scale, allows an unauthenticated attacker to trick a logged-in user into performing unintended actions, such as changing router settings, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (KEV), the vulnerability has garnered significant community discussion and media coverage, with proof-of-concept information available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.4.380.7266CPE matchmatch criteria | cpe:2.3:o:asus:rt-ac1750_firmware:3.0.0.4.380.7266:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.