First published: Mon Oct 15 2018(Updated: )
** DISPUTED ** An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC5300 firmware | ||
All of | ||
Asuswrt-Merlin project RT-AC1900P | <=380.70 | |
Asuswrt-Merlin project RT-AC1900P firmware | ||
All of | ||
Asuswrt-Merlin project RT-AC68U | <=380.70 | |
Asuswrt-Merlin project RT-AC68U firmware | ||
All of | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC68P firmware | ||
All of | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC88U firmware | ||
All of | ||
Asuswrt-Merlin project RT-AC66U B1 firmware | <=380.70 | |
Asuswrt-Merlin | ||
All of | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC56U firmware | ||
All of | ||
Asuswrt-Merlin project RT-AC3200 | <=380.70 | |
Asuswrt-Merlin project RT-AC3200 firmware | ||
All of | ||
Asuswrt-Merlin project rt-ac68uf | <=380.70 | |
Asuswrt-Merlin project rt-ac68uf firmware | ||
All of | ||
Asuswrt-Merlin project | <=380.70 | |
Asuswrt-Merlin project rt-ac87 firmware | ||
All of | ||
Asuswrt-Merlin project RT-AC3100 | <=380.70 | |
Asuswrt-Merlin project RT-AC3100 firmware | ||
All of | ||
Asuswrt-Merlin project rt-ac1900 | <=380.70 | |
Asuswrt-Merlin project rt-ac1900 firmware | ||
All of | ||
Asuswrt-Merlin project rt-ac86u | <=380.70 | |
Asuswrt-Merlin project rt-ac86u firmware | ||
All of | ||
Asuswrt-Merlin project rt-ac2900 | <=380.70 | |
ASUS Asuswrt-Merlin | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC5300 firmware | ||
Asuswrt-Merlin project RT-AC1900P | <=380.70 | |
Asuswrt-Merlin project RT-AC1900P firmware | ||
Asuswrt-Merlin project RT-AC68U | <=380.70 | |
Asuswrt-Merlin project RT-AC68U firmware | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC68P firmware | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC88U firmware | ||
Asuswrt-Merlin project RT-AC66U B1 firmware | <=380.70 | |
Asuswrt-Merlin | ||
ASUS Asuswrt-Merlin | <=380.70 | |
Asuswrt-Merlin project RT-AC56U firmware | ||
Asuswrt-Merlin project RT-AC3200 | <=380.70 | |
Asuswrt-Merlin project RT-AC3200 firmware | ||
Asuswrt-Merlin project rt-ac68uf | <=380.70 | |
Asuswrt-Merlin project rt-ac68uf firmware | ||
Asuswrt-Merlin project | <=380.70 | |
Asuswrt-Merlin project rt-ac87 firmware | ||
Asuswrt-Merlin project RT-AC3100 | <=380.70 | |
Asuswrt-Merlin project RT-AC3100 firmware | ||
Asuswrt-Merlin project rt-ac1900 | <=380.70 | |
Asuswrt-Merlin project rt-ac1900 firmware | ||
Asuswrt-Merlin project rt-ac86u | <=380.70 | |
Asuswrt-Merlin project rt-ac86u firmware | ||
Asuswrt-Merlin project rt-ac2900 | <=380.70 | |
ASUS Asuswrt-Merlin |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18319 has been classified as a high severity vulnerability due to the ability of attackers to execute arbitrary commands on affected devices.
To mitigate CVE-2018-18319, users should upgrade their Asuswrt-Merlin firmware to the latest version beyond 380.70 where the vulnerability is patched.
CVE-2018-18319 affects various Asuswrt-Merlin devices running firmware version up to 380.70, including RT-AC5300, RT-AC1900P, RT-AC68U, and several others.
CVE-2018-18319 can be exploited to execute arbitrary commands remotely through unprotected API calls.
Yes, the vendor has indicated that the issues related to Merlin.PHP are disputed and users are advised to follow up for the latest guidance.