CVE-2018-8877
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.
Affected (2)
Products: Asus: Asus Firmware · Asuswrt Merlin: Asuswrt Merlin
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.0.4.382.50470 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 384.4 |
References (2)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.