← Back

CVE-2018-8878

nvd nist
Published: Feb 27, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

Affected (2)

Asuswrt Merlin
1 product
Asus Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 384.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.0.0.4.382.50470

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.