First published: Thu Feb 27 2020(Updated: )
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asuswrt-merlin Asuswrt-merlin | <384.4 | |
Asus Asus Firmware | <3.0.0.4.382.50470 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8878 is a vulnerability in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 that allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses.
CVE-2018-8878 has a severity rating of 5.3, which is considered medium.
Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 are affected by CVE-2018-8878.
To fix CVE-2018-8878, update your Asuswrt-Merlin firmware to version 384.4 or newer, or update your ASUS firmware to version 3.0.0.4.382.50470 or newer.
The CWE ID for CVE-2018-8878 is 200.