{
    "id": "CVE-2017-6549",
    "published": "2017-03-09 09:59:00",
    "last_modified": "2026-06-17 01:22:32",
    "cvss_score": "8.8",
    "cvss_severity": "HIGH",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "cwe": "CWE-287",
    "description": "Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allows remote attackers to steal any active admin session by sending cgi_logout and asusrouter-Windows-IFTTT-1.0 in certain HTTP headers.",
    "epss_score": "0.07552",
    "epss_percentile": "0.94346",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-05 18:17:16",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "asus",
            "product": "rt-ac53"
        },
        {
            "vendor": "asus",
            "product": "rt-ac53_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "41572",
            "title": "ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Session Stealing",
            "date": "2017-03-08",
            "url": "https://www.exploit-db.com/exploits/41572"
        }
    ],
    "refs_list": [
        "http://www.securityfocus.com/bid/96938",
        "https://asuswrt.lostrealm.ca/changelog",
        "https://bierbaumer.net/security/asuswrt/#session-stealing",
        "https://www.exploit-db.com/exploits/41572/",
        "http://www.securityfocus.com/bid/96938",
        "https://asuswrt.lostrealm.ca/changelog",
        "https://bierbaumer.net/security/asuswrt/#session-stealing",
        "https://www.exploit-db.com/exploits/41572/"
    ]
}