CVE-2016-6557
Estado: ModificadaAlta (8.8)—
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-352
- CWE-352
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-6557",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "ASUS",
"product": "RP-AC52 Access Point",
"versions": [
{
"status": "affected",
"version": "1.0.1.1s"
}
]
}
]
}
],
"published": "2018-07-13T20:29:00.817",
"references": [
{
"url": "https://www.kb.cert.org/vuls/id/763843",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "https://www.securityfocus.com/bid/93596",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cret@cert.org"
},
{
"url": "https://www.kb.cert.org/vuls/id/763843",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.securityfocus.com/bid/93596",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cret@cert.org",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request."
},
{
"lang": "es",
"value": "En los puntos de acceso ASUS RP-AC52 con versiones de firmware 1.0.1.1s y posiblemente anteriores, la interfaz web no verifica lo suficiente si una petición válida ha sido proporcionada intencionadamente por el usuario. Un atacante puede realizar acciones con los mismos permisos que los del usuario víctima, siempre que la víctima tenga una sesión activa y sea inducida a desencadenar la petición maliciosa."
}
],
"lastModified": "2026-06-17T00:51:22.763",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:rp-ac52_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95CD566C-50C6-4D73-BDA5-707210513B0E",
"versionEndIncluding": "1.0.1.1s"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:rp-ac52:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8D3F3FE0-63F5-4D0F-9C3A-C1D39B16AED1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:ea-n66_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7C9567D-E5BA-42C9-A51A-05D431510B0B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:ea-n66:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7061553F-CA97-4021-A804-C29D1AE54AAF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:rp-n12_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A1B21FE-3A45-48DA-91BC-9A8CD8C7BD0C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:rp-n12:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E4291D2D-4C30-4E5A-94D9-0D465C9CFD88"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:rp-n14_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDB07468-ECC0-4A52-9BDA-A8207F467250"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:rp-n14:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F1B193A7-7C51-457C-A475-7DFF6458D4BF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:rp-n53_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0C97695-0E2B-461F-8C08-A4E709C67A77"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:rp-n53:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "39A8C124-CB6C-4F45-9C1B-0E52C59E42AD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:rp-ac56_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2C2FAC7-3DB8-4313-8AB6-2E1E8BE66201"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:rp-ac56:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "211D70E6-1FF9-4E0F-BA34-6A1329E4F01B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:asus:wmp-n12_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFA89FE0-E934-4519-B49C-FAAFBA26150B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:asus:wmp-n12:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E35AD500-683F-4C96-B0CE-74029076083F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cret@cert.org"
}