← Back

CVE-2018-18320

nvd nist
Published: Oct 15, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

Affected (14)

Rt Ac5300 Firmware
Rt Ac1900p Firmware
Rt Ac68u Firmware
Rt Ac68p Firmware
Rt Ac88u Firmware
Rt Ac66u B1 Firmware
Rt Ac56u Firmware
Rt Ac3200 Firmware
Rt Ac68uf Firmware
Rt Ac87 Firmware
Rt Ac3100 Firmware
Rt Ac1900 Firmware
Rt Ac86u Firmware
Rt Ac2900 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac5300
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac1900p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac68u
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac68p
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac88u
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac66u B1
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac56u
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac3200
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac68uf
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac87
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac3100
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac1900
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac86u
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 380.70
Running on/withPlatform Versions
Asuswrt Merlin Project
Rt Ac2900
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.