CVE-2018-18319: Code Injection
DISPUTED An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18319?
CVE-2018-18319 has been classified as a high severity vulnerability due to the ability of attackers to execute arbitrary commands on affected devices.
How do I fix CVE-2018-18319?
To mitigate CVE-2018-18319, users should upgrade their Asuswrt-Merlin firmware to the latest version beyond 380.70 where the vulnerability is patched.
Which devices are affected by CVE-2018-18319?
CVE-2018-18319 affects various Asuswrt-Merlin devices running firmware version up to 380.70, including RT-AC5300, RT-AC1900P, RT-AC68U, and several others.
What types of attacks can exploit CVE-2018-18319?
CVE-2018-18319 can be exploited to execute arbitrary commands remotely through unprotected API calls.
Is there a vendor response to CVE-2018-18319?
Yes, the vendor has indicated that the issues related to Merlin.PHP are disputed and users are advised to follow up for the latest guidance.