CVE-2018-18287: Infoleak
Published Oct 14, 2018
·Updated
On ASUS RT-AC58U 3.0.0.4.3806516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the MainLogin.asp page.
Affected Software
2 affected components
ASUS Rt-ac58u Firmware=3.0.0.4.380.6516
ASUS RT-AC58U
Event History
Oct 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this ASUS RT-AC58U issue?
The vulnerability ID for this ASUS RT-AC58U issue is CVE-2018-18287.
2
What is the severity of CVE-2018-18287?
The severity of CVE-2018-18287 is medium, with a CVSS score of 5.3.
3
How can remote attackers exploit CVE-2018-18287?
Remote attackers can exploit CVE-2018-18287 by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page on ASUS RT-AC58U devices.
4
What is the affected software version of CVE-2018-18287?
The affected software version of CVE-2018-18287 is ASUS RT-AC58U firmware version 3.0.0.4.380_6516.
5
Is the ASUS RT-AC58U device vulnerable to CVE-2018-18287?
Yes, ASUS RT-AC58U devices with firmware version 3.0.0.4.380_6516 are vulnerable to CVE-2018-18287.