CVE-2018-5721: Buffer Overflow
Stack-based buffer overflow in the ejupdatevariables function in router/httpd/web.c on ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) allows web authenticated attackers to execute code via a request that updates a setting. In ejupdatevariables, the length of the variable actionscript is not checked, as long as it includes a "wanif" substring.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5721?
CVE-2018-5721 is a vulnerability found in ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) that allows web authenticated attackers to execute code via a request that updates a setting.
How severe is CVE-2018-5721?
CVE-2018-5721 has a severity score of 8.8 (high).
How does CVE-2018-5721 affect ASUS routers?
CVE-2018-5721 affects ASUS routers running software from https://github.com/RMerl/asuswrt-merlin with version up to and including 382.1_2.
Is there a fix for CVE-2018-5721?
Unfortunately, there is no known fix for CVE-2018-5721 at the moment.
Where can I find more information about CVE-2018-5721?
You can find more information about CVE-2018-5721 at http://www.w0lfzhang.com/2018/01/17/ASUS-router-stack-overflow-in-http-server/