CVE-2023-31195
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted ('http') connection, the user's session may be hijacked.
| Vendor | asustek computer inc. |
| Product | asus router rt-ax3000 |
| Published | Jun 13, 2023 |
| Last Updated | Jan 3, 2025 |
Stay Ahead of the Next One
Get instant alerts for asustek computer inc. asus router rt-ax3000
Be the first to know when new medium vulnerabilities affecting asustek computer inc. asus router rt-ax3000 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ASUSTeK COMPUTER INC. / ASUS Router RT-AX3000
Firmware versions prior to 3.0.0.4.388.23403