CVE-2018-18320: Critical severity asuswrt-merlin rt-ac5300 firmware vulnerability
DISPUTED An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18320?
The severity of CVE-2018-18320 has been classified as medium due to the potential for arbitrary command execution.
How do I fix CVE-2018-18320?
To fix CVE-2018-18320, it is recommended to update to a version of Asuswrt-Merlin firmware newer than 380.70.
Which Asuswrt-Merlin devices are affected by CVE-2018-18320?
Asuswrt-Merlin devices running versions up to 380.70 are affected by CVE-2018-18320.
Can CVE-2018-18320 be exploited remotely?
CVE-2018-18320 requires an attacker to have access to the trusted intranet network to exploit it.
What component is involved in CVE-2018-18320?
CVE-2018-18320 involves the Merlin.PHP component in Asuswrt-Merlin firmware.