Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2017-15656
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
65.1%
CVSS Severity
CVSS v3 Score
8.8
CVSS v2 Score
4.0
References
http://packetstormsecurity.com/files/145921/ASUSWRT-3.0.0.4.382.18495-Session-Hijacking-Information-Disclosure.html
http://seclists.org/fulldisclosure/2018/Jan/63
http://packetstormsecurity.com/files/145921/ASUSWRT-3.0.0.4.382.18495-Session-Hijacking-Information-Disclosure.html
http://seclists.org/fulldisclosure/2018/Jan/63
Products affected by CVE-2017-15656
Asus
»
Asuswrt
»
Version:
N/A
cpe:2.3:o:asus:asuswrt:-
Asus
»
Asuswrt
»
Version:
3.0.0.4.378
cpe:2.3:o:asus:asuswrt:3.0.0.4.378
Asus
»
Asuswrt
»
Version:
3.0.0.4.380.7743
cpe:2.3:o:asus:asuswrt:3.0.0.4.380.7743
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved