CVE-2018-20333: Infoleak
Published Mar 20, 2020
·Updated
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /updateapplist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Affected Software
47 affected components
ASUS Asuswrt=3.0.0.4.384.20308
ASUS GT-AC2900
ASUS GT-AC5300
ASUS GT-AX11000
ASUS RT-AC1200
ASUS Rt-ac1200 V2
ASUS Rt-ac1200g
ASUS Rt-ac1200ge
ASUS RT-AC1750
ASUS Rt-ac1750 B1
ASUS RT-AC1900P
ASUS RT-AC3100
ASUS RT-AC3200
ASUS RT-AC51U
ASUS RT-AC5300
ASUS RT-AC55U
ASUS RT-AC56R
ASUS RT-AC56S
ASUS Rt-ac56u
ASUS RT-AC66R
ASUS RT-AC66U
ASUS Rt-ac66u-b1
ASUS RT-AC66U B1
ASUS Rt-ac68p
ASUS RT-AC68U
ASUS RT-AC86U
ASUS RT-AC87U
ASUS RT-AC88U
ASUS Rt-acrh12
ASUS RT-ACRH13
ASUS RT-AX3000
ASUS RT-AX56U
ASUS RT-AX58U
ASUS RT-AX88U
ASUS RT-AX92U
ASUS RT-G32
ASUS Rt-n10\+d1
ASUS RT-N10E
ASUS RT-N14U
ASUS RT-N16
ASUS Rt-n19
ASUS RT-N56R
ASUS RT-N56U
ASUS RT-N600
ASUS RT-N65U
ASUS RT-N66R
ASUS RT-N66U
Event History
Mar 20, 2020
CVE Published
via MITRE·12:11 AM
Data Sourced
via MITRE·12:11 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20333?
The severity of CVE-2018-20333 is high, with a severity value of 7.5.
2
How does CVE-2018-20333 affect ASUSWRT 3.0.0.4.384.20308?
CVE-2018-20333 allows an unauthenticated user to determine if a USB device is attached to the router and if there are apps installed on the router.
3
Is ASUS GT-AC2900 vulnerable to CVE-2018-20333?
No, ASUS GT-AC2900 is not vulnerable to CVE-2018-20333.
4
How can I fix CVE-2018-20333 in ASUSWRT 3.0.0.4.384.20308?
To fix CVE-2018-20333, update ASUSWRT to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2018-20333?
You can find more information about CVE-2018-20333 at the following link: [https://starlabs.sg/advisories/18-20333/](https://starlabs.sg/advisories/18-20333/)