Stack-based buffer overflow in the ejupdatevariables function in router/httpd/web.c on ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) allows web authenticated attackers to execute code via a request that updates a setting. In ejupdatevariables, the length of the variable actionscript is not checked, as long as it includes a "wanif" substring.