HTTP: Asus RT-G32 CVE-2015-2676 Cross Site Request Forgery

This signature detects attempts to exploit a known vulnerability against Asus RT-G32 Routers. A successful attack can lead to Cross Site Request Forgery.

Extended Description

Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm.

References

CVE: CVE-2015-2676

Short Name
HTTP:ASUS-RT-G32-CSRF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Asus CVE-2015-2676 Cross Forgery RT-G32 Request Site
Release Date
02/28/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

6.8

Found a potential security threat?