CVE-2018-20334: OS Command Injection
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /startapply.htm POST data, there is a command injection issue via shell metacharacters in the fbemail parameter. By using this issue, an attacker can control the router and get shell.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20334?
CVE-2018-20334 is an issue discovered in ASUSWRT 3.0.0.4.384.20308 that allows command injection via shell metacharacters.
How severe is CVE-2018-20334?
CVE-2018-20334 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2018-20334?
The ASUSWRT version 3.0.0.4.384.20308 is affected by CVE-2018-20334.
How can an attacker exploit CVE-2018-20334?
An attacker can exploit CVE-2018-20334 by using shell metacharacters in the fb_email parameter to execute arbitrary commands and gain control of the router and obtain shell access.
Where can I find more information about CVE-2018-20334?
You can find more information about CVE-2018-20334 at the following link: https://starlabs.sg/advisories/18-20334/