Rule Category

SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.

Alert Message

SERVER-WEBAPP Asus RT-AC88U deleteOfflineClients memory corruption attempt

Rule Explanation

This event is generated when an attempt to exploit CVE-2017-12754 is detected. Impact: Attempted Administrator Privilege Gain Details: This vulnerability is an instance of remote code execution on a vulnerable Asuswrt-merlin built router. An attacker who is able to access the deleteOfflineClient.cgi page may be able to cause an overflow which can redirect the flow of program execution, leading to possible device hijack. Ease of Attack:

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2017-12754
Loading description