CVE-2014-7270: ASUS Rt-AC56S

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allows remote attackers to hijack the authentication of arbitrary users.

Affected products

  • ASUS Rt-AC56S
  • ASUS Rt-AC56S Firmware: up to and including 3.0.0.4.376.3715
  • ASUS Rt-AC68U
  • ASUS Rt-AC68U Firmware: up to and including 3.0.0.4.376.3715
  • ASUS Rt-AC87U
  • ASUS Rt-AC87U Firmware: up to and including 3.0.0.4.378.3754
  • ASUS Rt-n56u
  • ASUS Rt-n56u Firmware: up to and including 3.0.0.4.376.3715
  • ASUS Rt-n66u
  • ASUS Rt-n66u Firmware: up to and including 3.0.0.4.376.3715

Published 2015-02-01. Last modified 2026-06-17.